Configuring the Kaspersky Endpoint Detection and Response (KATA) integration in the Web Console

In the Web Console, you can enable or disable the integration of Kaspersky Endpoint Security with Kaspersky Endpoint Detection and Response (KATA) and configure integration settings in the policy properties (Application settingsDetection and ResponseEndpoint Detection and Response (KATA)).

Managing Kaspersky Endpoint Detection and Response (KATA) Integration settings in Kaspersky Security Center Cloud Console is not supported.

Kaspersky Endpoint Detection and Response (KATA) integration settings

Setting

Description

Endpoint Detection and Response (KATA) enabled/disabled

Enables or disables the integration of the Kaspersky Endpoint Security application with Kaspersky Endpoint Detection and Response (KATA).

The integration server is disabled by default.

Server connection settings

Clicking the Configure link opens a window where you can configure general settings for connecting to KATA servers, add a server certificate, and configure two-way authentication when connecting to KATA servers.

KATA servers

The table contains a list of KATA servers to which connection is configured.

The Add button opens a window where you can configure the connection to the KATA server.

You can use the buttons above the table to edit and remove previously configured connection settings.

Maximum delay when sending events (sec)

The maximum delay in sending events to the KATA server in seconds.

The default value is 30.

Enable event throttling

Enables or disables regulating the number of events sent to the KATA server.

Maximum number of events per hour

Maximum number of events per hour

The default value is 3000.

Event throttle threshold (percentage)

Event throttle threshold (percentage). Sending events is limited if ratio of events of one type (for example, events about registry changes) to the total number of events exceeds the set threshold (as a percentage).

The default value is 15.

Page top