Configuring Kaspersky Security Center for export of events to a SIEM system

Expand all | Collapse all

You can enable automatic event export in Kaspersky Security Center.

Only general events can be exported from managed applications over the CEF and LEEF formats.  Application-specific events cannot be exported from managed applications over the CEF and LEEF formats. If you need to export events of managed applications or a custom set of events that has been configured using the policies of managed applications, you have to export the events in the Syslog format.

To enable automatic export of events:

  1. In the Kaspersky Security Center console tree, select the Administration Server whose events you want to export.
  2. In the workspace of the selected Administration Server, select the Events tab.
  3. Click the drop-down arrow next to the Configure notifications and event export link, and then select Configure export to SIEM system in the drop-down list.

    The events properties window opens, displaying the Event export section.

  4. In the Event export section, specify the following export settings:

    In the Event export section, export settings are specified.

    Event export section of the event properties window

    • Automatically export events to SIEM system database
    • SIEM system

      If you select the Syslog format, you must specify:

      Maximum message size, in bytes

    • SIEM system server address
    • SIEM system server port
    • Protocol
  5. If you want to export to the SIEM system database the events that occurred after a specified date in the past, click the Export archive button, and then specify the start date for event export. By default, the event export starts immediately after you enable it.
  6. To check that the SIEM system connection is successfully configured, click the Test settings button.

    The application tries to establish connection with the SIEM system server and send a test event. The connection status is displayed.

  7. Click OK.

Automatic export of events is enabled.

After enabling automatic export of events, you must select which events will be exported to the SIEM system.

See also:

Scenario: Configuring event export to SIEM systems

Marking of events for export to SIEM systems in Syslog format

Page top