Kaspersky Embedded Systems Security 3.4 for Windows

Generating a Kaspersky Security Center blocked devices report

You can import data on blocked connection attempts from devices from a report generated in Kaspersky Security Center as a result of running the Device Control task, and use this data to create a list of device control allow rules in a custom policy.

To generate a Kaspersky Security Center blocked devices report:

  1. In the Kaspersky Security Center Administration Console tree, expand the Managed devices node.
  2. Select the administration group you want to run a blocked devices report for.
  3. Select the Policies tab.
  4. Open the policy properties window by double-clicking the name of the policy configured to collect data on blocked devices.
  5. In the Properties: <Policy name> window that opens, go to Logs and notifications.
  6. Under Task logs, click Settings.

    A Logs settings window opens on the Logs tab.

  7. Select Device Control from the Component drop-down list.
  8. Select Custom from the Importance level drop-down list.
  9. In the list of events, select the Untrusted external device detected and restricted and Statistics only: untrusted external device detected check boxes.
  10. Clear the check boxes next to the other events in the list.
  11. In the Log storage section, make sure that the Device Control log retention period exceeds the planned period of collecting data on blocked devices. The default is 30 days.

    Once the Device Control log retention period expires, logged events will be deleted and will not appear in the report.

  12. Activate the policy configured to collect blocked devices data.
  13. If required, modify the Device Control mode.
  14. When the period allocated for collecting blocked devices data expires, go to the Device Control log storage folder. Its path is specified in the Logs settings policy window on the Logs tab, in the Logs folder field.
  15. Open the Device Control TXT log.
  16. If required, adjust the list of events in the Device Control log.