Kaspersky Endpoint Security 12 for Windows

Kaspersky Unified Monitoring and Analysis Platform (KUMA)

July 23, 2024

ID 274395

Kaspersky Endpoint Security for Windows supports the Kaspersky Unified Monitoring and Analysis Platform solution. Kaspersky Unified Monitoring and Analysis Platform (KUMA) is a security information and event management (SIEM) solution for the IT infrastructure of organizations. KUMA allows detecting, analyzing, and mitigating security threats before they can cause harm.

Kaspersky Endpoint Security is installed on individual computers on the corporate IT infrastructure and continuously monitors processes, open network connections, and files being modified. Information about events on the computer (telemetry) is sent to the Kaspersky Unified Monitoring and Analysis Platform (KUMA) server. In its console, KUMA displays events as a list without markup, similar to the Windows event log. To access all KUMA functionality, you need to purchase a license and deploy the solution in accordance with the KUMA Administrator's guide.

Integration with KUMA

To use KUMA, the following conditions must be met:

  • Kaspersky Security Center version 14.2 or higher. In earlier versions of Kaspersky Security Center, it is impossible to activate the KUMA integration functionality.
  • The application is activated and the functionality is covered by the license.
  • The KUMA integration component is enabled.

Setting up KUMA integration involves the following steps:

  1. Installing the KUMA integration component

    You can select the KUMA integration component when installing or upgrading the application, as well as using the Change application components task.

    You must restart your computer to finish upgrading the application with the new component.

  2. KUMA activation

    You need a separate license to integrate Kaspersky Endpoint Security with KUMA (Kaspersky Endpoint Security for Windows KUMA Integration Add-on).

    The functionality becomes available after adding the separate KUMA key. As a result, there will be another active key on the computer for Kaspersky Endpoint Security integration with KUMA.

    Licensing for the stand-alone KUMA functionality is the same as the licensing of Kaspersky Endpoint Security.

    Make sure that the KUMA functionality is included in the license and is working in the local interface of the application.

  3. Connecting to KUMA

    To connect the computer with the Kaspersky Endpoint Security application to the KUMA solution:

    1. In the Kaspersky Endpoint Security policy, add KUMA server addresses and specify network settings of the connection.
    2. In KUMA console, add a collector with connectors of the tcp or udp type and specify the basic network settings of the connection. For details about managing collectors, please refer to the Kaspersky Unified Monitoring and Analysis Platform Help.

    You can establish a trusted connection between Kaspersky Endpoint Security and KUMA servers. To configure a trusted connection, you must use a TLS certificate. You can get a TLS certificate on the KUMA Core server (see the settings for the tcp type connector in the Kaspersky Unified Monitoring and Analysis Platform Help). Then you must add the TLS certificate to Kaspersky Endpoint Security (see instructions below).

    To make the connection more secure, you can additionally enable the verification of the computer in KUMA (two-way authentication). To enable this verification, you must turn on two-way authentication in KUMA and Kaspersky Endpoint Security settings. To use two-way authentication, you will also need a crypto-container. A crypto-container is a PFX archive with a certificate and a private key. You must generate a certificate with the private key in the PKCS#12 container format in an external certification authority. Then you must add the PFX archive in the KUMA console and in Kaspersky Endpoint Security (see the settings for the tcp type connector in the Kaspersky Unified Monitoring and Analysis Platform Help).

    How to connect a Kaspersky Endpoint Security computer to KUMA using the Administration Console (MMC)

    How to connect a Kaspersky Endpoint Security computer to KUMA using the Web Console

You can verify that the receipt of Windows events is configured correctly in the KUMA console (for details see Kaspersky Unified Monitoring and Analysis Platform Help). Check the operating status of the component by viewing the Application components status report in the Kaspersky Security Center console. You can also view the operating status of a component in reports in the local interface of Kaspersky Endpoint Security. The KUMA Integration component will be added to the list of Kaspersky Endpoint Security components.

Did you find this article helpful?
What can we do better?
Thank you for your feedback! You're helping us improve.
Thank you for your feedback! You're helping us improve.