Viewing events
19 January 2023
ID 201952
You can view events in the following ways:
- In the application event log. The event log is located in the directory specified by the
EventsStoragePath
general application setting. By default, the application saves information about events to the following database directory /var/opt/kaspersky/kesl/private/storage/events.db. Root privileges are required to access the database of events. - In the general application settings, if the
UseSysLog
setting has the valueYes
, then event data is also written to syslog. Root privileges are required to access syslog. - Enable output of current application events using the
kesl-control -W
command. - If Kaspersky Endpoint Security is managed by Kaspersky Security Center, information about events may be transmitted to the Kaspersky Security Center Administration Server. If three events of the same type, from the same initiator, with the same name are created within one minute, then the application switches to event aggregation mode and sends one aggregated event that describes these recurring events to Kaspersky Security Center every 10 minutes. Kaspersky Endpoint Security administrator can configure the execution of a script upon receiving events from the application or upon receiving notifications about events by e-mail. For more information about events, refer to Kaspersky Security Center documentation.
- If the graphical user interface (GUI) is enabled, information about events can be viewed in reports and in application pop-up windows.
To get information about all events in the event log, run the following command:
kesl-control -E --query|less
By default, the application stores up to 500,000 events. You can use the less
command to navigate through the list of displayed events.
You can view specific events using the application's event store query system.
When creating a query, specify the required field, select a logical expression, and specify the required value for it. The value must be specified in single quotation marks ('), and the whole query must be specified in double quotation marks ("):
--query "<
field
> <
logical expression
> '<
value
>' [and <
field
> <
logical expression
> '<
value
>' *]"
The date field should be specified in the UNIX time stamp system (the number of seconds that have elapsed since 00:00:00 (UTC), 1 January 1970).
ThreatDetected example:
|
Query examples: Get all events by the EventType field:
Display all events with the specified values of the EventType and FileName fields:
Display all events generated by the File_Threat_Protection task after the specified time:
|