In the main Kaspersky Security Center Web Console window select Devices → Managed devices.
Select the device for which you want to configure application settings.
In the <Device name> window that opens, select the Applications tab.
Select Kaspersky Endpoint Agent.
In the Kaspersky Endpoint Agent window that opens, select the Application settings tab.
In the Telemetry collection servers section, select Integration with SIEM.
The Integration with SIEM window opens.
In the Connection settings section, use the corresponding check box to enable integration with a SIEM system.
In the List of SIEM servers settings block, add the settings for connecting to one or more SIEM servers:
Click the Add button.
The SIEM server settings window opens.
In the corresponding field, enter the domain name or IP address of the SIEM server.
In the Port field, enter the port for connecting to the SIEM server.
In the Protocol drop-down list, select the protocol used for data transfer between Kaspersky Endpoint Agent and the SIEM server.
Click Add.
The settings for connecting to the SIEM server will be displayed in the List of SIEM servers settings block.
If necessary, repeat steps a – e to add settings for connecting to other SIEM servers.
Kaspersky Endpoint Agent connects to the first SIEM server in the list. If the connection does not succeed, Kaspersky Endpoint Agent connects to the second SIEM server and so on down the list.
In the upper right corner of the settings group, change the switch from Undefined to Enforce.
The default switch position is Enforce.
Click OK.
Integration with SIEM will be enabled immediately after the policy is applied.