Kaspersky Security Center allows you to configure the settings for exporting events in the CEF format to a SIEM system.
The function of exporting Kaspersky Security Center events in the CEF format to SIEM systems is available with Kaspersky Endpoint Security for Business Advanced license or above.
To configure export of events from Kaspersky Security Center Administration Server to the KUMA SIEM system:
The Properties: Events window opens. By default the Events export section is displayed.
You can click Export archive and specify the starting date from which pre-existing KUMA events are to be exported to the SIEM system database. By default, Kaspersky Security Center exports events starting from the current date.
As a result, the Kaspersky Security Center Administration Server automatically exports all events to the KUMA SIEM system.
Configuring export of Kaspersky Security Center events to the KUMA SIEM system
Page top