Configuring Kaspersky Security Center Cloud Console for export of events to a SIEM system

Expand all | Collapse all

To export events to a SIEM system, you have to configure the process of export in Kaspersky Security Center Cloud Console.

To configure export to SIEM systems in the Kaspersky Security Center Cloud Console:

  1. In the main menu, click the settings icon () next to the name of the required Administration Server.

    The Administration Server properties window opens.

  2. On the General tab, select the SIEM section.
  3. Click the Settings link.

    The Export settings section opens.

  4. Specify the settings in the Export settings section:
    • SIEM system server address
    • SIEM system port
    • Protocol
  5. If you want, you can export archived events from the Administration Server database and set the start date from which you want to start the export of archived events:
    1. Click the Set the export start date link.
    2. In the section that opens, specify the start date in the Date to start export from field.
    3. Click the OK button.
  6. Switch the option to the Automatically export events to SIEM system database Enabled position.
  7. To check that the SIEM system connection is successfully configured, click the Check connection button.

    The connection status will be displayed.

  8. Click the Save button.

Export to a SIEM system is configured. From now on, if you configured the receiving of events in a SIEM system, Administration Server exports the marked events to a SIEM system. If you set the start date of export, Administration Server also exports the marked events stored in the Administration Server database from the specified date.

See also:

Scenario: configuring event export to SIEM systems

Configuring an event export in a SIEM system

Page top