This Kaspersky Security Center OpenAPI reference guide is designed to assist in the following tasks:
In the OpenAPI reference guide, you can use the search field in the right part of the screen to locate the information you need.
Samples of scripts
The OpenAPI reference guide contains samples of the Python scripts listed in the table below. The samples show how you can call OpenAPI methods and automatically accomplish various tasks for protecting your network, for instance, create a "primary/secondary" hierarchy, run tasks in Kaspersky Security Center, or assign distribution points. You can run the samples as is or create your own scripts based on the samples.
To call the OpenAPI methods and run scripts:
You can call the OpenAPI methods, run the samples and your own scripts only on devices where Administration Server and the KlAkOAPI package are installed.
Matching between user scenarios and samples of Kaspersky Security Center OpenAPI methods
Sample |
Purpose of the sample |
Scenario |
---|---|---|
You can extract and process data by using the The sample output may be present in different ways. You can get the data to send an HTTP method or to use it in your code. |
||
You can add a secondary Administration Server and establish a "primary/secondary" hierarchy. Alternately, you can disconnect the secondary Administration Server from the hierarchy. |
||
Create the group hierarchy with a structure based on the Active Directory unit |
You can poll the Active Directory unit and form a hierarchy of discovered device groups. |
|
Create the group hierarchy with a structure based on the cached Active Directory unit |
You can form a hierarchy of the managed device groups based on the Active Directory unit polled earlier. If new devices appear in the Active Directory after the last polling, they are not added into the group because they are not in the saved polling results. |
|
Download network list files via connection gateway to the specified device |
You can connect to Network Agent on the needed device by using a connection gateway, and then download a file with the network list to your device. |
|
You can connect to the primary Administration Server, download a required license key from it, and transmit this key to all the secondary Administration Servers included in a hierarchy. |
||
You can create different reports. For instance, you can generate the report of effective user rights by using this sample. This report describes the rights that a user has, depending on his or her group and role. You can download the report in the HTML, PDF, or Excel format. |
||
You can connect to Network Agent on the needed device by using a connection gateway, and then run the necessary task. |
||
Create IP subnets based on Active Directory Site and Services |
You can create an IP subnet based on the Active Directory unit that you use. The sample launches polling of the specified IP range and deletes discovered subnets to avoid their conflict with a new subnet. Therefore, do not run this sample in the network where it is important to keep subnets. After polling, the sample refers to the Active Directory, examines every device in it, and creates the IP subnet. To do this, the sample uses masks and IP addresses of all devices. |
|
You can assign managed devices as distribution points (previously known as update agents). |
||
You can perform various actions with administration groups. The sample shows how to do the following:
|
||
You can find out the following information:
You can also run a task. By default, the sample runs a task after it outputs statistics. |
||
You can create a task. Specify the following task parameters in the sample:
By default, the sample creates a task with the "Show message" type. You can run this task for all managed devices of Administration Server. If necessary, you can specify your own task parameters. |
||
You can get a list of all the active license keys for Kaspersky applications installed on managed devices of Administration Server. The list contains detailed data about every license key, such as a name, type, or expiration date. |
||
You can create an account for further work. |
||
You can create the application category with the needed parameters. |
Creating an application category with content added manually |
|
You can use the SrvView class to request detailed information from the Administration Server. For instance, you can get a list of users by using this sample. |
Applications interacting with Kaspersky Security Center via OpenAPI
Some applications interact with Kaspersky Security Center via OpenAPI. Such applications include, for example, Kaspersky Anti Targeted Attack Platform or Kaspersky Security for Virtualization. This can also be a custom client application developed by you based on OpenAPI.
Applications interacting with Kaspersky Security Center via OpenAPI connect to Administration Server. If you have configured an allowlist of IP addresses for connecting to the Administration Server, add IP addresses of devices where applications using Kaspersky Security Center OpenAPI are installed. To find out whether the application that you use works by OpenAPI, see Help of this application.
Page top