Kaspersky Anti Targeted Attack (KATA) Platform

Configuring receipt of mirrored traffic from SPAN ports and the http-body parameter

26 June 2024

ID 273355

If you are using the distributed solution and multitenancy mode, use the web interface of the PCN or SCN server for which you want to configure parameters.

To configure receipt of mirrored traffic from SPAN ports:

  1. Select the Sensor servers section in the window of the application web interface.

    The Server list table will be displayed.

  2. Select the Sensor server for which you want to configure the receipt of mirrored traffic from SPAN ports.

    This opens the Sensor server settings page.

  3. Select the SPAN traffic processing section.

    The Network interfaces table is displayed.

  4. In the row of the network interface from which you want to configure the receipt of mirrored traffic, set the toggle switch in the SPAN traffic scanning column to Enabled.
  5. Under Dump HTTP body:
    • If you want to enable the http-body parameter in the Suricata configuration file, set the toggle switch to Enabled. By default, the toggle switch is in the Enabled position.
    • If you want to disable the http-body parameter in the Suricata configuration file, set the toggle switch to Disabled.
  6. Click Apply.

Receipt of mirrored traffic from SPAN ports and the http-body parameter are configured.

Did you find this article helpful?
What can we do better?
Thank you for your feedback! You're helping us improve.
Thank you for your feedback! You're helping us improve.