Integration of Kaspersky Endpoint Security with KUMA

To use KUMA, the following conditions must be met:

Setting up KUMA Integration involves the following steps:

  1. Installing the KUMA integration component

    You can select the KUMA integration component when installing or upgrading the application, as well as using the Change application components task.

    You must restart your computer to finish upgrading the application with the new component.

  2. KUMA activation

    In addition to a Kaspersky Endpoint Security application license (for example, Kaspersky Endpoint Security for Business Standard), you need a separate license for the integration of Kaspersky Endpoint Security with KUMA (Kaspersky Endpoint Security for Windows KUMA Integration Add-on).

    If you are installing the application in EDR Agent mode, you need a license for integrating Kaspersky Endpoint Security with KUMA and a Kaspersky Anti Targeted Attack Platform (KATA) license or a Kaspersky Managed Detection and Response (MDR) license. You cannot deploy EDR Agent for KUMA only.

    The functionality becomes available after adding the separate KUMA key. As a result, there will be another active key on the computer for Kaspersky Endpoint Security integration with KUMA.

    Licensing for the stand-alone KUMA functionality is the same as the licensing of Kaspersky Endpoint Security.

    Make sure that the KUMA functionality is included in the license and is working in the local interface of the application.

  3. Connecting to KUMA

    To connect the computer with the Kaspersky Endpoint Security application to the KUMA solution:

    1. In the Kaspersky Endpoint Security policy, add KUMA server addresses and specify network settings of the connection.
    2. In KUMA console, add a collector with connectors of the tcp or udp type and specify the basic network settings of the connection. For details about managing collectors, please refer to the Kaspersky Unified Monitoring and Analysis Platform Help.

    You can establish a trusted connection between Kaspersky Endpoint Security and KUMA servers. To configure a trusted connection, you must use a TLS certificate. You can get a TLS certificate on the KUMA Core server (see the settings for the tcp type connector in the Kaspersky Unified Monitoring and Analysis Platform Help). Then you must add the TLS certificate to Kaspersky Endpoint Security (see instructions below).

    To make the connection more secure, you can additionally enable the verification of the computer in KUMA (two-way authentication). To enable this verification, you must turn on two-way authentication in KUMA and Kaspersky Endpoint Security settings. To use two-way authentication, you will also need a crypto-container. A crypto-container is a PFX archive with a certificate and a private key. You must generate a certificate with the private key in the PKCS#12 container format in an external certification authority. Then you must add the PFX archive in the KUMA console and in Kaspersky Endpoint Security (see the settings for the tcp type connector in the Kaspersky Unified Monitoring and Analysis Platform Help).

    How to connect a Kaspersky Endpoint Security computer to KUMA using the Administration Console (MMC)

    How to connect a Kaspersky Endpoint Security computer to KUMA using the Web Console

    You can verify that KUMA integration is configured correctly in the KUMA console (for details see Kaspersky Unified Monitoring and Analysis Platform Help). Check the operating status of the component by viewing the Application components status report in the Kaspersky Security Center console. You can also view the operating status of a component in reports in the local interface of Kaspersky Endpoint Security. The KUMA Integration component will be added to the list of Kaspersky Endpoint Security components.

Page top