Kaspersky Security Center

Configuring Kaspersky Security Center Linux for export of events to a SIEM system

2024年5月6日

ID 216090

Expand all | Collapse all

To export events to a SIEM system, you have to configure the process of export in Kaspersky Security Center Linux.

To configure export to SIEM systems in the Kaspersky Security Center Web Console:

  1. In the main menu, click the settings icon () next to the name of the required Administration Server.

    The Administration Server properties window opens.

  2. On the 常规 tab, select the SIEM section.
  3. Click the 设置 link.

    The 导出设置 section opens.

  4. Specify the settings in the 导出设置 section:
    • SIEM 系统服务器地址
    • SIEM 系统端口
    • 协议
  5. If you want, you can export archived events from the Administration Server database and set the start date from which you want to start the export of archived events:
    1. Click the 设置导出起始日期 link.
    2. In the section that opens, specify the start date in the 导出的起始日期 field.
    3. Click the 确定 button.
  6. Switch the option to the 自动导出事件至 SIEM 系统数据库已启用 position.
  7. Click the 保存 button.

Export to a SIEM system is configured. From now on, if you configured the receiving of events in a SIEM system, Administration Server exports the marked events to a SIEM system. If you set the start date of export, Administration Server also exports the marked events stored in the Administration Server database from the specified date.

See also:

About configuring event export in a SIEM system

Did you find this article helpful?
What can we do better?
Thank you for your feedback! You're helping us improve.
Thank you for your feedback! You're helping us improve.