Searching for events from Kaspersky Scan Engine version 2.1
To search KUMA for events sent by Kaspersky Scan Engine version 2.1:
DeviceVendor = Kaspersky
AND
DeviceProduct = Scan Engine ICAP Service
KUMA search query for Kaspersky Scan Engine in ICAP mode
DeviceVendor = Kaspersky
AND
DeviceProduct = Scan Engine HTTP Service
KUMA search query for Kaspersky Scan Engine in HTTP mode
Searching for events from Kaspersky Scan Engine version 2.0
To search KUMA for events sent by Kaspersky Scan Engine version 2.0:
DeviceVendor = Kaspersky Lab
AND
DeviceProduct = Kaspersky ICAP Server
DeviceVendor = Kaspersky Lab
AND
DeviceProduct = Kaspersky HTTP Service