Kaspersky Security 11.x for Windows Server

Configuring log settings in Administration Plug-in

June 10, 2022

ID 148501

You can edit the following settings of Kaspersky Security for Windows Server logs:

  • Length of the storage period for events in task logs and the system audit log.
  • Location of the folder in which Kaspersky Security for Windows Server stores task log files and the system audit log file.
  • Events generation thresholds for Application database is out of date, Application database is extremely out of date and Critical areas scan has not been performed for a long time.
  • Events that Kaspersky Security for Windows Server saves in task logs, the system audit log, and the event log of Kaspersky Security for Windows Server in Event Viewer.
  • Settings for publishing audit events and task performance events to the syslog server via the Syslog protocol.

To configure Kaspersky Security for Windows Server logs, perform the following steps:

  1. In the Application Console tree, open the context menu of the Logs and notifications node and select Properties.

    The Logs and notifications settings window opens.

  2. In the Logs and notifications settings window, configure the logs in accordance with your requirements. To do this, perform the following actions:
    • On the General tab, if necessary, select events that Kaspersky Security for Windows Server will save in task logs, the system audit log, and the event log of Kaspersky Security for Windows Server in Event Viewer. To do this, perform the following actions:
      • In the Component list, select the component of Kaspersky Security for Windows Server for which you want to set the detail level.

      For the Real-Time File Protection, RPC Network Storage Protection, ICAP Network Storage Protection, Script Monitoring, On-Demand Scan, and Update components, events are recorded in tasks logs and the event log. For these components, the event table contains the Task log and Windows Event Log columns. Events for the Quarantine and Backup components are registered in the system audit log and the event log. For these components, the event table contains the Audit and Windows Event Log columns.

      • In the Importance level list, select a detail level for events in task logs, the system audit log, and the event log for the selected component.

        In the following table with a list of events, the check boxes are selected next to events that are registered in task logs, the system audit log, and the event log, according to the current detail level.

      • If you want to manually enable registration of specific events for a selected component, perform the following actions:
      1. In the Importance level list, select Custom.
      2. In the table with the list of events, select the check boxes next to events that you want to be registered in task logs, the system audit log, and the event log.
    • On the Advanced tab, configure the log storage settings and event generation thresholds for device protection status:
      • In the Log storage section:
        • Logs folder
        • Remove task logs older than (days)
        • Remove from the system audit log events older than (days)
      • In the Event generation thresholds section:
        • Specify the number of days after which the Application database is out of date, Application database is extremely out of date and Critical areas scan has not been performed for a long time events will occur.

    • On the SIEM integration tab, configure the settings for publishing audit events and task performance events to the syslog server.
  3. Click OK to save the changes.

In this section

About SIEM integration

Configuring SIEM integration settings

Did you find this article helpful?
What can we do better?
Thank you for your feedback! You're helping us improve.
Thank you for your feedback! You're helping us improve.