Kaspersky Next XDR Expert
Response rules for Open Single Management Platform

You can configure response rules to automatically start tasks of anti-virus scan and updates on Open Single Management Platform assets.

When creating and editing response rules for Open Single Management Platform, you need to define values for the following settings.

Response rule settings

Setting

Description

Name

Required setting.

Unique name of the resource. Must contain 1 to 128 Unicode characters.

Tenant

Required setting.

The name of the tenant that owns the resource.

Type

Required setting, available if KUMA is integrated with Open Single Management Platform.

Response rule type, ksctasks.

Open Single Management Platform task

Required setting.

Name of the Open Single Management Platform task to run. Tasks must be created beforehand, and their names must begin with "KUMA". For example, KUMA antivirus check (not case-sensitive and without quotation marks).

You can use KUMA to run the following types of Open Single Management Platform tasks:

  • Update
  • Virus scan

Event field

Required setting.

Defines the event field of the asset for which the Open Single Management Platform task should be started. Possible values:

  • SourceAssetID
  • DestinationAssetID
  • DeviceAssetID

Handlers

The number of handlers that the service can run simultaneously to process response rules in parallel. By default, the number of handlers is the same as the number of virtual processors on the server where the service is installed.

Description

Description of the response rule. You can add up to 4,000 Unicode characters.

Filter

Used to define the conditions for the events to be processed using the response rule. You can select an existing filter from the drop-down list or create a new filter.

Creating a filter in resources

To send requests to Open Single Management Platform, you must ensure that Open Single Management Platform is available over the UDP protocol.

If a response rule is owned by the shared tenant, the displayed Open Single Management Platform tasks that are available for selection are from the Open Single Management Platform server that the main tenant is connected to.

If a response rule has a selected task that is absent from the Open Single Management Platform server that the tenant is connected to, the task is not performed for assets of this tenant. This situation could arise when two tenants are using a common correlator, for example.