Kaspersky Security 11.x for Windows Server

Filling rules list basing on Device Control task events

June 10, 2022

ID 148414

To create a configuration file that contains device control rules list basing on the Device Control task events:

  1. Start the Device Control task in the Statistics only mode, to log all events of flash drives and other external devices connections to a protected device.
  2. Upon the completion of the task in the Statistics only mode, open the task log by clicking the Open task log button in the Management section of the Device Control node results pane.
  3. In the Logs window click the Generate rules based on events.

Kaspersky Security for Windows Server will create an XML configuration file that contains a rules list generated basing on events of the Device Control task in the Statistics only mode. You can apply this list in the Device Control task.

Before applying a rules list generated basing on the task events, it is recommended to review and then manually process the rules list to make certain that there are no untrusted devices allowed by the specified rules.

During the conversion of an XML file with the task events to a rules list, the application generates allowing rules for all registered events, including the devices restrictions.

All the task events are registered in the task log regardless of the task mode. You can create a configuration file with a rules list basing on the events of the task in the Active mode. This scenario is not recommended except urgent cases, as far as the task efficiency requires to generate a final rule list version before the task is run in the active mode.

Did you find this article helpful?
What can we do better?
Thank you for your feedback! You're helping us improve.
Thank you for your feedback! You're helping us improve.