Enabling and configuring exclusions for and optimization of sent EDR telemetry about application processes

Expand all | Collapse all

You can configure exclusions for and optimization of the volume of EDR telemetry about application processes using Kaspersky Security Center Administration Console, in the properties of an individual device or in the policy settings for a group of devices.

Exclusions of sent EDR telemetry about application processes are available when integrating Kaspersky Endpoint Agent with servers on which KATA Central Node or Kaspersky Industrial CyberSecurity for Networks is installed.

Kaspersky Endpoint Agent does not analyze or send data on excluded application processes to the server with KATA Central Node or Kaspersky Industrial CyberSecurity for Networks installed.

Optimization of the amount of sent EDR telemetry about application processes can be managed (enabled/disabled) when Kaspersky Endpoint Agent is integrated with servers with Kaspersky Industrial CyberSecurity for Networks installed.

If optimization of the amount of sent EDR telemetry is enabled, Kaspersky Endpoint Agent does not send events with codes 102 (basic communications) and 8 (the process's network activity) for the Microsoft SMB protocol and Network Agent klnagent.exe about application processes to a server on which Kaspersky Industrial CyberSecurity for Networks is installed.

To enable and configure exclusions for and optimization of the volume of EDR telemetry on application processes:

  1. Do one of the following:
    • Open the application properties window for an individual device.
    • Open the policy properties window.
  2. Select the EDR telemetryExcluded processes section.
  3. In the Exclusions settings group, enable the Use exclusions setting to enable use of EDR telemetry exclusions.
  4. Configure optimization of the volume of EDR telemetry:

    When integrating Kaspersky Endpoint Agent with servers with KATA Central Node installed, optimization of the amount of sent EDR telemetry should always be enabled.

    • Disable the Optimize the amount of telemetry setting if you want Kaspersky Endpoint Agent to send events with codes 102 (basic communications) and 8 (the process's network activity) for the Microsoft SMB protocol, WinRM service, and the Network Agent process klnagent.exe, as well as extended information about the type of network packets for all types of network protocols.
    • Enable the Optimize the amount of telemetry setting if you want Kaspersky Endpoint Agent to not send events with codes 102 (basic communications) and 8 (the process's network activity) for the Microsoft SMB protocol and the Network Agent process klnagent.exe, as well as extended information about the type of network packets for all types of network protocols.

    If the Use exclusions setting is disabled, Kaspersky Endpoint Agent does not send events with codes 102 (basic communications) and 8 (the process's network activity) for the Microsoft SMB protocol and the Network Agent process klnagent.exe, as well as extended information about the type of network packets for all types of network protocols, regardless of the value of the Optimize the amount of telemetry setting.

  5. Create a list of exclusions:
    1. Click the Add button.
    2. In the Rule properties window that opens, configure the exclusion settings

      Please note that when specifying parameters of the executable file manually, the Description field in the File properties section should either be left empty or correspond to the value of the FileDescription parameter from the resource of the RT_VERSION type (VersionInfo). In any other cases rule will not work.

    3. Click OK to save the changes and close the Rule properties window.

      The new exclusion is created and displayed in the list of exclusions.

    4. If you need to export the exclusion list to an XML file, click the Export button.
    5. If you need to import the exclusion list from an XML file, click the Import button.
    6. If you need to modify an exclusion, click the Modify button.
    7. If you need to delete an exclusion from the list, select the exclusion and click the Delete button.
  6. If you are configuring the policy settings, make sure that the switch in the upper right corner of the group of settings is turned on.
  7. Click OK to save the changes.
Page top