Kaspersky Anti Targeted Attack (KATA) Platform

Modifications of application settings for disconnecting an SCN from PCN

8 November 2023

ID 247902

Modifications of application settings after an SCN is disconnected from the PCN are listed in the following table.

Modifications of application settings after disconnecting an SCN from PCN

Functional area

PCN

SCN

Users

The disconnected SCN is not removed from the list of servers to which user rights apply.

Information about changes of the user account that has rights on the disconnected SCN is not sent to the SCN.

User accounts received from the PCN are not deleted.

You can create new user accounts again, as well as disable and change passwords for existing user accounts.

Alerts

Alert information on the disconnected SCN is deleted.

Operation history and all alert information is preserved.

Tasks

Tasks created on the disconnected SCN are deleted.

Tasks created on the PCN are deleted.

Information about users who created tasks on the SCN is preserved.

Reports

All reports created earlier concerning the disconnected SCN are preserved, as well as the ability to filter the report list by this server.

Templates and reports are not modified.

Prevention

Policies created on the disconnected SCN are deleted.

Policies created on the PCN are deleted.

Information about users who created policies on the SCN is preserved.

Storage

All objects related to the disconnected SCN are deleted from Storage.

All objects in the Storage are preserved.

The link to the task stops working in information about objects received as part of tasks created on the PCN.

TAA exclusions

No changes.

No changes.

VIP status

No changes.

No changes.

Notification rules

No changes.

No changes.

Integration with mail sensors

No changes.

No changes.

Threat Hunting

After the search query is processed, events related to the disconnected SCN are not displayed.

No changes.

Custom rules ‑ TAA and IOC

IOC and TAA (IOA) rules of a disconnected SCN are deleted.

IOC and TAA (IOA) rules created on the PCN are deleted.

Backup of the application

Backup of the application remains unavailable.

Backup of the application becomes available.

See also

Distributed solution and multitenancy mode transition scenario

Modifications of application settings for the distributed solution and multitenancy mode

Assigning the PCN role to a server

Assigning the SCN role to a server

Processing SCN to PCN connection requests

Viewing information about tenants, PCN and SCN servers

Adding a tenant to the PCN server

Deleting a tenant from the PCN server

Renaming a tenant on the PCN server

Disconnecting an SCN from PCN

Decommissioning an SCN server

Did you find this article helpful?
What can we do better?
Thank you for your feedback! You're helping us improve.
Thank you for your feedback! You're helping us improve.