Kaspersky Unified Monitoring and Analysis Platform

Special consideration for successful export from the KUMA hierarchical structure to NCIRCC

April 8, 2024

ID 243256

If multiple KUMA nodes combined into a hierarchical structure are deployed in your organization, you can forward incidents, which are received from the child KUMA nodes, from the KUMA parent nodes to NCIRCC. For this purpose, the following conditions must be met:

  • Integration with NCIRCC is configured in the parent and child KUMA nodes. The URL and Token settings in the SettingsNCIRCC section are required for the parent node but are not required for the child node.
  • NCIRCC integration is enabled in both nodes.

In this case, interaction with NCIRCC is performed only at the level of the node exporting the incident to NCIRCC.

Settings of the incident received from a child KUMA node cannot be changed from a parent KUMA node. If there is not enough data for performing NCIRCC export, the incident must be changed at the child KUMA node, and then exported to NCIRCC from the parent KUMA node.

Did you find this article helpful?
What can we do better?
Thank you for your feedback! You're helping us improve.
Thank you for your feedback! You're helping us improve.