Kaspersky Unified Monitoring and Analysis Platform

Response rules for KICS for Networks

You can configure response rules to automatically trigger response actions on KICS for Networks assets. For example, you can change the asset status in KICS for Networks.

When creating and editing response rules for KICS for Networks, you need to define values for the following settings:

  • Name (required)—unique name of the resource. Must contain from 1 to 128 Unicode characters.
  • Tenant (required)—name of the tenant that owns the resource.
  • Type (required)—kics.
  • Event field (required)—event field containing the asset for which the response actions are needed. Possible values:
    • SourceAssetID
    • DestinationAssetID
    • DeviceAssetID
  • KICS for Networks task—response action to be performed when data matching the filter is received. The following types of response actions are available:
    • Change asset status to Authorized.
    • Change asset status to Unauthorized.

    When a response rule is triggered, KUMA will send KICS for Networks an API request to change the status of the specified device to Authorized or Unauthorized.

  • Workers—the number of processes that the service can run simultaneously.

    By default, the number of workers is the same as the number of virtual processors on the server where the service is installed.

  • Description—you can add up to 4000 Unicode characters describing the resource.
  • Filter—used to define the conditions for the events to be processed by the response rule resource. You can select an existing filter resource from the drop-down list or create a new filter.

    Creating a filter in resources