Kaspersky Unified Monitoring and Analysis Platform

Configuring the export of Kaspersky Security Center events to the KUMA SIEM system

KUMA allows you to receive and export events from the Kaspersky Security Center Administration Server to the KUMA

.

Configuring the export and receipt of Kaspersky Security Center events involves of the following steps:

  1. Configuring the export of Kaspersky Security Center events.
  2. Configuring the KUMA Collector.
  3. Installing the KUMA collector in the network infrastructure.
  4. Verifying the receipt of Kaspersky Security Center events by KUMA.

    You can verify if the events from Kaspersky Security Center Administration Server were correctly exported to the KUMA SIEM system by using the KUMA web interface to search for related events.

    To display Kaspersky Security Center events in the table, enter the following search expression:

    SELECT * FROM `events` WHERE DeviceProduct = 'KSC' ORDER BY Timestamp DESC LIMIT 250

In this section

Configuring export of Kaspersky Security Center events in CEF format

Configuring KUMA collector for collecting Kaspersky Security Center events

Installing KUMA collector for collecting Kaspersky Security Center events