Filtering events to be sent to SIEM

To improve performance and optimize data transmission to the SIEM server, you can manually add or exclude individual events from telemetry. For example you can exclude Sysmon events.

Kaspersky Industrial CyberSecurity for Nodes supports up to 1500 inclusion and exclusion rules for filtering telemetry events in total.

How to create a list of events to be sent to your SIEM in the Kaspersky Security Center Administration Console

How to create a list of events to be sent to SIEM in Web Console

Page top