Kaspersky Unified Monitoring and Analysis Platform
Special consideration for successful export from the KUMA hierarchical structure to RuCERT

If multiple KUMA nodes combined into a hierarchical structure are deployed in your organization, you can forward incidents, which are received from the child KUMA nodes, from the KUMA parent nodes to RuCERT. For this purpose, the following conditions must be met:

  • Integration with RuCERT is configured in the parent and child KUMA nodes. The URL and Token settings in the SettingsRuCERT section are required for the parent node but are not required for the child node.
  • RuCERT integration is enabled in both nodes.

In this case, interaction with RuCERT is performed only at the level of the node exporting the incident to RuCERT.

Settings of the incident received from a child KUMA node cannot be changed from a parent KUMA node. If there is not enough data for performing RuCERT export, the incident must be changed at the child KUMA node, and then exported to RuCERT from the parent KUMA node.