Kaspersky Endpoint Agent

Configuring the Security audit task settings using a custom database from file

September 13, 2022

ID 231842

This Help provides information related to Kaspersky Endpoint Agent for Windows. This information may be partially or completely inapplicable to Kaspersky Endpoint Agent for Linux. For complete information about Kaspersky Endpoint Agent for Linux, please refer to the Help of the solution that includes the application: Kaspersky Anti Targeted Attack Platform or Kaspersky Managed Detection and Response.

The task can be run only if you have an active Kaspersky Industrial CyberSecurity for Nodes license key with an ICS Audit licensed object.

To configure the Security audit task settings:

  1. In the main Kaspersky Security Center Web Console window select DevicesTasks.
  2. Open the task settings window by clicking the task name.
  3. Select the Application settings tab.
  4. In the Source section, select User database from file, click Import OVAL collection from file, and select the appropriate file from the list.

    You can download one ZIP file containing an XML file with OVAL rules. The XML file does not require a signature. The total size of the file with OVAL rules and the file with external variables must not exceed 2 MB.

    Click OK to confirm your selection.

    After you select the rule source, the Source tab displays data on OVAL rules uploaded by Kaspersky Security Center administrator to the server.

  5. To download a file with external variables, select the Use data with external variables for custom databases check box and click Import external variables from file.
  6. In the Scope section, select the action for the Run a scan task in the selected mode option:
    • Scan all definitions
    • Scan definitions, except for the ones in the following list
    • Scan only definitions included in the list below

      Click Save to save and apply the selected settings.

  7. In the Advanced settings section, select the settings based on your requirements:
    • Select the Apply directives check box and specify the Directive settings.
    • Select the Enable logging check box and select the desired Logging level from the list.

    Click Save to save and apply the selected settings.

    You can start the created task manually or configure a scheduled task start.

Did you find this article helpful?
What can we do better?
Thank you for your feedback! You're helping us improve.
Thank you for your feedback! You're helping us improve.