Kaspersky Anti Targeted Attack (KATA) Platform

Configuring integration with an SIEM system

8 November 2023

ID 247568

Kaspersky Anti Targeted Attack Platform can publish information about user actions in the application web interface as well as alerts to a SIEM system already in use at your organization using the Syslog protocol.

You can use TLS encryption for data transmission.

If you have deployed the Central Node and Sensor components as a cluster, you can configure fault-tolerant integration with an external system using one of the following options:

  • Using the Round Robin function.
  • Configure the settings of the external system so that the external system switches between the IP addresses of the cluster servers if a network error occurs.

To configure fault-tolerant integration with an external system using the Round Robin function:

  1. Configure Round Robin on the DNS server for the domain name corresponding to the Central Node cluster.
  2. Specify this domain name in the mail server settings.

Integration with the mail server will be configured based on the domain name. The mail server will communicate with a random server in the cluster. If this server fails, the mail server will communicate with another healthy server in the cluster.

In this section

Enabling and disabling information logging to a remote log

Configuring the main settings for SIEM system integration

Uploading a TLS certificate

Enabling and disabling TLS encryption of the connection with the SIEM system

Content and properties of syslog messages about alerts

Did you find this article helpful?
What can we do better?
Thank you for your feedback! You're helping us improve.
Thank you for your feedback! You're helping us improve.