Click Update in the event details area containing the data received from the Kaspersky Threat Intelligence Portal.
The Threat Lookup enrichment area opens in the right part of the screen.
Select the check boxes next to the types of information you want to request.
If neither check box is selected, all information types are requested.
In the Maximum number of records in each data group field enter the number of entries per selected information type you want to receive. The default value is 10.
Click Update.
The KTL task is created and the new data received from Kaspersky Threat Intelligence Portal is requested.
Close the Threat Lookup enrichment window and the details area with KTL information.
Open the event details area from the events table, Alert window or correlation event window and click the link on a domain, URL, IP address, or file hash for which you updated Kaspersky Threat Intelligence Portal information and select Show info from Threat Lookup.
The event details area opens on the right with data from Kaspersky Threat Intelligence Portal, indicating the time when it was received on the bottom of the screen.