Click Update in the event details area containing the data received from the Kaspersky Threat Intelligence Portal.
The KTL enrichment area opens in the right part of the screen.
Select the check boxes next to the types of information you want to request.
If neither check box is selected, all information types are requested.
In the Maximum number of records in each data group field enter the number of entries per selected information type you want to receive. The default value is 10.
Click Update.
The KTL task is created and new data is requested received from Kaspersky Threat Intelligence Portal.
Close the KTL enrichment window and the details area with KTL information.
Open the event details area from the events table, Alert window or correlation event window and click the link on a domain, URL, IP address, or file hash for which you updated Kaspersky Threat Intelligence Portal information and select Show information in KTL.
The event details area opens on the right with data from Kaspersky Threat Intelligence Portal, indicating the time when it was received on the bottom of the screen.