Kaspersky Machine Learning for Anomaly Detection

First startup of Kaspersky MLAD

December 6, 2023

ID 247994

This section describes the sequence of application configuration steps that must be performed by the system administrator when Kaspersky MLAD is started for the first time.

The first startup of Kaspersky MLAD consists of the following steps:

  1. Starting Kaspersky MLAD

    Start Kaspersky MLAD. The following services required for Kaspersky MLAD operation will be started:

    • API Server.
    • Web Server.
    • Message Broker.
    • Keeper.
    • Time Series Database.
    • Database.
    • Logger
  2. Connecting to the Kaspersky MLAD web interface

    Open the application web interface in a supported browser and enter the user name and password of the first Kaspersky MLAD user with the system administrator role defined during installation of the application. Change the password for your user account. For a secure connection to Kaspersky MLAD web interface, install a trusted certificate.

  3. Configuring services

    In the System parameters section of the administrator menu, configure the services that you need to use for your monitored asset. In the Services section, check the statuses of the services and start them, if necessary. For example, the Anomaly Detector service must be running for correct anomaly detection.

  4. Uploading a configuration of tags and assets of the hierarchical structure to Kaspersky MLAD and creating presets

    Configuration of tags, assets and presets is created by a Kaspersky expert or integrator while deploying the application and building an ML model. Tag and asset configuration is described in a XLSX file. A preset configuration is described in a JSON file. For examples of descriptions of the configuration of tags and assets, as well as preset configuration, see the Appendix.

    For subsequent operation, upload tag and asset configuration to Kaspersky MLAD. Download preset configuration or create new presets from tags.

  5. Uploading and creating ML models

    An ML model is not included in the application distribution kit but is provided as part of the Kaspersky MLAD Model-building and Deployment Service.

    Download the ML model, if it was provided as part of the Kaspersky MLAD Model-building and Deployment Service, or create it yourself using the Model Builder. Activate the downloaded ML model. To activate the ML model, you must enter a model activation code.

  6. Configuring connectors

    To work with data, configure the connectors used at your monitored asset. You can configure the following connectors:

  7. Connecting to a data source

    When the above connectors are configured, start the connectors used for your monitored asset. Go to the Dashboard section and make sure that data is being received by Kaspersky MLAD in online mode.

  8. Configure attention

    To work with events and patterns, configure attention settings and display of event parameters. The Event Processor service detects events and patterns only for the attention directions defined in the attention settings.

  9. Creating user accounts

    Create accounts for users of the application and assign the necessary roles to them. Configure incident notifications for users.

Kaspersky Machine Learning for Anomaly Detection is prepared for operation, and the application is receiving and processing data.

Users can start working with Kaspersky MLAD using the web interface.

Did you find this article helpful?
What can we do better?
Thank you for your feedback! You're helping us improve.
Thank you for your feedback! You're helping us improve.