Kaspersky Endpoint Agent

Enabling integration with a SIEM system

November 17, 2023

ID 265771

To enable integration with a SIEM system:

  1. Expand the Managed devices node in the Kaspersky Security Center Administration Console tree.
  2. Select the administration group for which you want to configure application settings.
  3. Perform one of the following actions in the details pane of the selected administration group:
    • To configure application settings for a group of protected devices, select the Policies tab and open the Properties: <Policy name> window.
    • To configure the settings of a task or application for an individual protected device, select the Devices tab and go to the settings of a local task or the application settings.
  4. In the Telemetry collection servers section, select the SIEM integration subsection.
  5. In the Connection settings section, use the corresponding check box to enable integration with a SIEM system.
  6. In the List of SIEM servers settings block, add the settings for connecting to one or more SIEM servers:
    1. Click the Add button.

      The Server properties window will open.

    2. In the corresponding field, enter the domain name or IP address of the SIEM server.
    3. In the Port field, enter the port for connecting to the SIEM server.
    4. In the Protocol drop-down list, select the protocol used for data transfer between Kaspersky Endpoint Agent and the SIEM server.
    5. Click Add.

      The settings for connecting to the SIEM server will be displayed in the List of SIEM servers settings block.

    6. If necessary, repeat steps a – e to add settings for connecting to other SIEM servers.

    Kaspersky Endpoint Agent connects to the first SIEM server in the list. If the connection does not succeed, Kaspersky Endpoint Agent connects to the second SIEM server and so on down the list.

  7. In the upper right corner of the settings group, change the switch from Policy not enforced to Under policy.
  8. Click OK.

Integration with SIEM will be enabled immediately after the policy is applied.

See also

Integration with a SIEM system

Did you find this article helpful?
What can we do better?
Thank you for your feedback! You're helping us improve.
Thank you for your feedback! You're helping us improve.