Kaspersky Endpoint Agent

Configuring settings for synchronization of Kaspersky Endpoint Agent with a SIEM server

17 November 2023

ID 265776

To configure the time to wait for a response from the SIEM server:

  1. Expand the Managed devices node in the Kaspersky Security Center Administration Console tree.
  2. Select the administration group for which you want to configure application settings.
  3. Perform one of the following actions in the details pane of the selected administration group:
    • To configure application settings for a group of protected devices, select the Policies tab and open the Properties: <Policy name> window.
    • To configure the settings of a task or application for an individual protected device, select the Devices tab and go to the settings of a local task or the application settings.
  4. In the Telemetry collection servers section, select the SIEM integration subsection.
  5. In the Connection settings section, in the Timeout period (sec.) field, specify the time to wait for a response from the SIEM server.

    When the specified time expires, Kaspersky Endpoint Agent tries to connect to the same server again or connects to the next server in the list, if there are multiple servers. The default value is 10 seconds.

  6. In the upper right corner of the settings group, change the switch from Policy not enforced to Under policy.
  7. Click OK.

See also

Integration with a SIEM system

Enabling integration with a SIEM system

Did you find this article helpful?
What can we do better?
Thank you for your feedback! You're helping us improve.
Thank you for your feedback! You're helping us improve.