Kaspersky Endpoint Agent

Configuring a secure connection with a SIEM server

November 17, 2023

ID 265774

To configure a secure connection between Kaspersky Endpoint Agent and a SIEM server:

  1. Do one of the following:
    • To configure the SIEM integration settings for a group of protected devices, open the application policy properties window.
    • To configure the SIEM integration settings for an individual protected device, open the application settings for the device.
  2. In the Telemetry collection servers section, select Integration with SIEM.

    The Integration with SIEM window opens.

  3. In the Connection settings block, select the Use TLS encryption check box to encrypt data transfer between Kaspersky Endpoint Agent and the SIEM server.
  4. If you want to configure additional connection protection using a pinned TLS certificate:
    1. Select the Use pinned certificate to protect connection check box.
    2. Add a TLS certificate:
      1. Click the Add new TLS certificate button.
      2. In the window that opens, do one of the following:
        • Click Browse, and in the window that opens, select the certificate file and click Open.
        • Copy and paste the contents of the certificate file to the Paste TLS certificate data field.
      3. Click OK.

      Information about the added TLS certificate is shown in the TLS certificate data group of settings.

  5. If you want to configure additional connection protection using a user certificate:
    1. In the Additional connection protection section, select the Secure connection with the client certificate check box.
    2. Click the Load Crypto-container button.
    3. In the window that opens, select the PFX file that stores the client certificate in encrypted form.
    4. Click Open.
    5. In the Cryptocontainer password field, enter the password for the PFX file.
  6. Click OK.
  7. In the upper right corner of the settings group, change the switch from Undefined to Enforce.

    The default switch position is Enforce.

  8. Click OK.

A secure connection with the SIEM server is configured.

See also

Integration with a SIEM system

Enabling integration with a SIEM system

Did you find this article helpful?
What can we do better?
Thank you for your feedback! You're helping us improve.
Thank you for your feedback! You're helping us improve.