What do you need help with?

We are here and ready to help.
Email: servicedesk@socfortress.co

Kaspersky Security Center (on-prem) - Syslog Forwarder

Kaspersky Security Center (on-prem) - Syslog Forwarder

Kaspersky Security Center “takes the complexity out of security administration and IT systems management. Fully scalable, the console supports growing businesses with changing security needs, and facilitates comprehensive systems and security management, with easy separation of administrator responsibilities — all from one unified management console also available as a web-based console”.

 

Prerequisites

To replicate this article, it’s imperative to ensure that you have met the following:

  • Advanced or Management license installed.
  • Kaspersky Security Center: A version 14.2 installed and operational.
  • Kaspersky Endpoint Security: A version 12.5.0 Installed on a Windows (any version supported).

Kaspersky Security Center Setup

To enable your SIEM to log and alert on events being generated by Kaspersky Security Center and Kaspersky Endpoint Security, we need to configure some important settings:

  1. Open Kaspersky Center Security
  2. Select Events
  3. Select Configure notifications and event export and open Configure export to SIEM

Press enter or click to view image in full size

KSC Events configuration
  1. Navigate to Event export.
  2. Check Automatically export events to SIEM system database.
  3. Under SIEM system: Set syslog RFC 5424. Server address, Port, and Protocol will be provided by the SOCFortress team.
  4. Hit Apply to finish.
Press enter or click to view image in full size
KSC SIEM export settings
  1. Right-click under Administration Server and open Properties.
  1. Navigate to Event configuration.
  2. These are all events and their level of severity supported by Kaspersky Security Center. For the sake of the article, we will select severity Info.
  3. Select Audit: Object has been modified.
  4. Open Properties.
Press enter or click to view image in full size
KSC Events Types
  1. Check Store in the Administration Server database for (days) and Export to SIEM system using Syslog.
  2. Hit OK and Apply to finish.

 

Facebook Share Tweet

Was this article helpfu?

Yes No

Thank you for voting

×
Select company

You are related to multiple companies. Please select the company you wish to login as.