Kaspersky Anti Targeted Attack Platform can publish information about user actions in the program web interface as well as alerts to a SIEM system already in use at your organization using the Syslog protocol.
You can use TLS encryption for data transmission.
If you have deployed the Central Node and Sensor components as a cluster, you can configure fault-tolerant integration with an external system using one of the following options:
To configure the fault-tolerant integration with the external system:
Integration with the mail server will be configured based on the domain name. The mail server will communicate with a random server in the cluster. If this server fails, the mail server will communicate with another healthy server in the cluster.