In some cases, it is necessary for Kaspersky CyberTrace Service to send responsive alerts back to the event source to the same socket from which the original events are received (ReplyBack mode).
To shift Kaspersky CyberTrace Service to ReplyBack mode:
Send X-KF-ReplyBack as the first message after a TCP connection with Kaspersky CyberTrace Service is established.
During the current TCP session every responsive alert will be sent back to the same socket from which the original event was received. The setting specified in the OutputSettings > ConnectionString element of the configuration file will be ignored.
You can configure Kaspersky CyberTrace Service to send an alert indicating that event checking has finished.
To enable sending finishing alerts, perform one of the following actions:
enable attribute of the OutputSettings > FinishedEventFormat element of the Kaspersky CyberTrace Service configuration file to true.X-KF-SendFinishedEventX-KF-ReplyBack as the first message after a TCP connection with Kaspersky CyberTrace Service is established.In this case, the enable attribute of the OutputSettings > FinishedEventFormat element in the Kaspersky CyberTrace Service configuration file will be ignored.
To instruct Kaspersky CyberTrace Service that it must shift to ReplyBack mode and send finishing alerts:
Send X-KF-SendFinishedEventX-KF-ReplyBack as the first message after a TCP connection with Kaspersky CyberTrace Service is established.
By default, in ReplyBack mode, Kaspersky CyberTrace does not save the statistics of the detection alerts received during the current connection.
To save the statistics of the detection alerts in ReplyBack mode:
X-KF-SendFinishedEventX-KF-ReplyBackX-KF-SaveStatistic as the first message after a TCP connection with Kaspersky CyberTrace Service is established.X-KF-ReplyBackX-KF-SaveStatistic as the first message after a TCP connection with Kaspersky CyberTrace Service is established.