Enable the Knowledge Base Module
The LogRhythm Knowledge Base UEBA module contains rules that make use of LogRhythm UEBA outputs. To take full advantage of the use cases, the module must be enabled.
To enable the module:
- Log in to the LogRhythm Client Console as a Global Administrator.
- On the main toolbar, click Tools, click Knowledge, and then click Knowledge Base Manager.
The Knowledge Base Manager appears. - In the Knowledge Base Modules grid, select the Action check box for the User and Entity Behavior Analytics module.
- Right-click the selected module, click Actions, and then click Enable Module.
- To close the Knowledge Base Manager, click OK.
- On the main toolbar, click Deployment Manager.
- Click the AI Engine tab.
- Select the Action check boxes for the CloudAI rules.
- Right-click the selection, click Actions, and then click Enable.
- At the bottom of the window, click the Workloads tab.
- In the Workloads grid, select the default Workload.
- In the Rule Sets grid, select the Action check box of the Rule Set that contains the UEBA rules.
- Right-click the selection, click Actions, and then click Include in Workload.
The Include Rule Sets message box appears. - To assign the Rules to the Workload, click OK.
The Rules Included confirmation message appears. - Click OK.