Kaspersky Machine Learning for Anomaly Detection

Events are not transmitted between Kaspersky MLAD and external systems

December 6, 2023

ID 248116

Problem

Events are not received by Kaspersky MLAD and/or alerts about the monitor activation are not sent to external systems.

Solution

To restore the exchange of events with external systems:

  1. Start the Event Processor service and the CEF Connector.
  2. When configuring the Event Processor service, do the following:
    1. In the Event processor configuration file field, upload the configuration file describing the event parameters.
    2. In the Interval for receiving batch events (sec.) field, specify the time interval in seconds required to generate an episode, taking into account the speed of receiving events from the monitored asset.
  3. To receive events in the .env file, specify the port number used to connect to the external event source.
  4. To send events, when configuring the CEF Connector, specify the IP address and the port number for connecting to the external system.

Did you find this article helpful?
What can we do better?
Thank you for your feedback! You're helping us improve.
Thank you for your feedback! You're helping us improve.