Integration of the built-in agent with EDR Expert (on-premise)

To integrate with Kaspersky Endpoint Detection and Response Expert (on-premise) solution, you must add the Endpoint Detection and Response Expert (on-premise) component, and configure Kaspersky Endpoint Security.

EDR Optimum, EDR Expert, and EDR Expert (on-premise) components are not compatible with each other.

The following conditions must be fulfilled for Endpoint Detection and Response Expert (on-premise) to work:

Setting up EDR Expert (on-premise) Integration involves the following steps:

  1. Installing the EDR Expert (on-premise) component

    You can select the EDR Expert (on-premise) component during installation or upgrade, as well as using the Change application components task.

    You must restart your computer to finish upgrading the application with the new component.

  2. Activating Kaspersky Endpoint Detection and Response Expert (on-premise)

    You need to purchase a separate license for EDR Expert (on-premise) (Kaspersky Endpoint Detection and Response Expert (on-premise) Add-on).

    The functionality becomes available after adding a separate key for Kaspersky Endpoint Detection and Response Expert (on-premise). As a result, two keys are added on the computer: a key for Kaspersky Endpoint Security and a key for Kaspersky Endpoint Detection and Response Expert (on-premise).

    Licensing for the stand-alone Endpoint Detection and Response Expert (on-premise) functionality is the same as the licensing of Kaspersky Endpoint Security.

    Make sure that the EDR Expert (on-premise) functionality is included in the license and is running in the local interface of the application.

  3. Connecting to telemetry collection server and response server

    Kaspersky Endpoint Detection and Response Expert (on-premise) requires a trusted connection between Kaspersky Endpoint Security and two servers:

    • A telemetry collection server is a server that is part of a SIEM solution that collects, normalizes, correlates, analyzes, and stores information about events occurring on the computer.
    • A response server is a server for receiving and scanning data, studying the behavior of objects, and publishing the results of such studies.

    To configure a trusted connection, you must use a TLS certificate. You can get a TLS certificate on the Open Single Management Platform (see instructions in the Kaspersky Endpoint Detection and Response Expert (on-premise) Help). Then you must add the TLS certificate to Kaspersky Endpoint Security (see instructions below).

    By default, Kaspersky Endpoint Security only checks the TLS certificate of the servers. To make the connection more secure, you can additionally enable the verification of the computer on the server (two-way authentication). To enable this verification, you must turn on two-way authentication in the server and Kaspersky Endpoint Security settings. To use two-way authentication, you will also need a crypto-container. A crypto-container is a PFX archive with a certificate and a private key. You can get a crypto-container on the Open Single Management Platform (see instructions in the Kaspersky Endpoint Detection and Response Expert (on-premise) Help).

    How to connect a Kaspersky Endpoint Security computer to EDR Expert (on-premise) using the Web Console

    As a result, the computer is added on the Open Single Management Platform (OSMP). Check the operating status of the component by viewing the Report on status of application components. You can also view the operating status of a component in reports in the local interface of Kaspersky Endpoint Security. The Endpoint Detection and Response Expert (on-premise) component will be added to the list of Kaspersky Endpoint Security components.

Page top