In the Reporting Device field, specify the devices from which the events must be forwarded to Kaspersky CyberTrace. You can select All to indicate that events from every device must be forwarded to Kaspersky CyberTrace.
For more choices, click the down arrow to open the Event Dropping Rule > Select Reporting Devices window, and make selections in the Folders, Items, and Selections panes.
The Reporting Device field must not be empty.
In the Event type field, specify the types of events that must be forwarded to Kaspersky CyberTrace. You can select All to indicate that events of every type must be forwarded to Kaspersky CyberTrace.
For more choices, click the down arrow to open the Event Forwarding Rule > Select Event Types window, and make selections in the Folders, Items, and Selections panes.
Selecting event types
The Event type field must not be empty.
In the Traffic Type field, select Syslog.
In the Source IP field, you can specify the value that must be present in all the forwarded events in the corresponding field.
In the Destination IP field, you can specify the value that must be present in all the forwarded events in the corresponding field.
In the Severity fields, you can specify the desired severity of events.
In the Regex Filter field, you can specify the regular expression to which must forwarded events match.
In the Forwarding Protocol field, select TCP.
In the Forwarding to IP field, specify the IP address of the computer on which Kaspersky CyberTrace runs.