Viewing events that occurred during the last run of the System Integrity Check

January 10, 2024

ID 64733

You can view the events that occurred during the last System Integrity Check via the Kaspersky Security properties installed on the protected virtual machine. You can view the list of events using Administration Console or Web Console (in the properties window of Kaspersky Security for Virtualization 5.2 Light Agent installed on the virtual machine, on the Application settings tab in the System Integrity Monitoring events section).

To use the Administration Console to view the list of events that occurred on the virtual machine during the last run of the System Integrity Check task:

  1. Open Kaspersky Security Center Administration Console.
  2. In the Managed devices folder in the console tree, select the folder with the name of the administration group that includes the required virtual machine.
  3. In the workspace, select the Devices tab.
  4. Select a virtual machine from the list and double-click it to open the Settings: <Virtual machine name> window.
  5. In the window that opens, in the list on the left, select the Applications section.
  6. In the right part of the window, in the list of applications installed on the virtual machine, select Kaspersky Security for Virtualization 5.2 Light Agent and double-click it to open the Kaspersky Security for Virtualization 5.2 Light Agent Settings window.
  7. In the window that opens, in the list on the left, select the System Integrity Monitoring events section.

    The table in the right part of the window shows the following information about each event:

    • Event generation date.
    • Event name.
    • Rule applied by the System Integrity Monitoring component.
    • Control object in which the modification is made. Depending on the type of control object, the following information is displayed in the column:
      • Path to the file, if the System Integrity Monitoring component detected a change to a file.
      • Registry key, if the System Integrity Monitoring component detected a change in the registry.
      • Device name, if the System Integrity Monitoring component detected the connection of an external device.
    • Type of modification to the monitored object detected by the System Integrity Monitoring component. Possible values:
      • Create.
      • Modify.
      • Delete.
      • Connect.

    In the list of events, you can perform the following actions:

    • Update the list of events.
    • Filter the list of events by column values or custom conditions.
    • Use the search function to find a specific event.
    • Change the order and arrangement of columns that are shown in the report.
    • Sort the list of events by each column.
    • Save a report to a TXT or CSV file.

Did you find this article helpful?
What can we do better?
Thank you for your feedback! You're helping us improve.
Thank you for your feedback! You're helping us improve.