<?xml version="1.0"?>
<rss version="2.0"><channel><title><![CDATA[Советы и решения по Kaspersky Anti Targeted Attack & EDR Expert Latest Topics]]></title><link>https://forum.kaspersky.com/forum/%D1%81%D0%BE%D0%B2%D0%B5%D1%82%D1%8B-%D0%B8-%D1%80%D0%B5%D1%88%D0%B5%D0%BD%D0%B8%D1%8F-%D0%BF%D0%BE-kaspersky-anti-targeted-attack-edr-expert-226/</link><description><![CDATA[Советы и решения по Kaspersky Anti Targeted Attack & EDR Expert Latest Topics]]></description><language>en</language><item><title>&#x41A;&#x430;&#x43A; &#x443;&#x441;&#x442;&#x440;&#x430;&#x43D;&#x438;&#x442;&#x44C; &#x43E;&#x448;&#x438;&#x431;&#x43A;&#x443; &#x43F;&#x43E;&#x434;&#x43A;&#x43B;&#x44E;&#x447;&#x435;&#x43D;&#x438;&#x44F; &#x43A; KSN [KATA/KEDRE]</title><link>https://forum.kaspersky.com/topic/%D0%BA%D0%B0%D0%BA-%D1%83%D1%81%D1%82%D1%80%D0%B0%D0%BD%D0%B8%D1%82%D1%8C-%D0%BE%D1%88%D0%B8%D0%B1%D0%BA%D1%83-%D0%BF%D0%BE%D0%B4%D0%BA%D0%BB%D1%8E%D1%87%D0%B5%D0%BD%D0%B8%D1%8F-%D0%BA-ksn-katakedre-37666/</link><description><![CDATA[<p>
	 
</p>

<h2 style="background-color:#ffffff;border-bottom-color:#7eff33;color:#000000;font-size:20px;padding:0px;">
	<strong style="background-color:#ffffff;color:#444444;font-size:14px;"><span style="font-size:14px;"><a href="https://forum.kaspersky.com/topic/%D0%B4%D0%B8%D1%81%D0%BA%D0%BB%D0%B5%D0%B9%D0%BC%D0%B5%D1%80-%D0%BE%D0%B1%D1%8F%D0%B7%D0%B0%D1%82%D0%B5%D0%BB%D1%8C%D0%BD%D0%BE-%D0%BA-%D0%BF%D1%80%D0%BE%D1%87%D1%82%D0%B5%D0%BD%D0%B8%D1%8E-%D0%BF%D0%B5%D1%80%D0%B5%D0%B4-%D0%B8%D1%81%D0%BF%D0%BE%D0%BB%D1%8C%D0%B7%D0%BE%D0%B2%D0%B0%D0%BD%D0%B8%D0%B5%D0%BC-%D0%BC%D0%B0%D1%82%D0%B5%D1%80%D0%B8%D0%B0%D0%BB%D0%BE%D0%B2-%D0%B1%D0%B0%D0%B7%D1%8B-%D0%B7%D0%BD%D0%B0%D0%BD%D0%B8%D0%B9-%D1%84%D0%BE%D1%80%D1%83%D0%BC%D0%B0-36969/#comment-148890" rel="" style="background-color:transparent;color:#00a88e;"><span style="color:#e74c3c;">Дисклеймер. Обязательно к прочтению перед использованием материалов базы знаний Форума.</span></a></span></strong>
</h2>

<h2 style="background-color:rgb(255,255,255);border-bottom-color:rgb(126,255,51);font-size:20px;padding:0px;">
	<font color="#339966">Проблема</font>
</h2>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	В веб-интерфейсе KATA может появиться ошибка подключения к KSN.
</p>

<h2 style="background-color:#ffffff;border-bottom-color:#7eff33;color:#000000;font-size:20px;padding:0px;">
	<span style="color:#339966;">Решение</span>
</h2>

<p>
	Ошибку подключения к KSN можно исправить, если только нет других постоянных ошибок KSN. Это можно проверить на уровне DEBUG ksn_proxy.log. Ключевое слово — ErrCount. Если вы не видите Errcount: 0 в журнале, значит, у вас нет доступа к нашим серверам:
</p>

<ul style="background-color:#ffffff;color:#172b4d;font-size:14px;">
	<li>
		<span>*.<a href="http://ksn.kaspersky-labs.com/" rel="external nofollow" style="background-color:transparent;color:#265951;">ksn.kaspersky-labs.com</a></span>
	</li>
	<li>
		<span>ksn-*.<a href="http://kaspersky-labs.com/" rel="external nofollow" style="background-color:transparent;color:#265951;">kaspersky-labs.com</a></span>
	</li>
	<li>
		<span><a href="http://ds.kaspersky.com/" rel="external nofollow" style="background-color:transparent;color:#265951;">ds.kaspersky.com</a></span>
	</li>
</ul>

<h3 style="background-color:#ffffff;color:#000000;font-size:16px;padding:0px;">
	KATA 4.0/4.1
</h3>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	           Под root в центральном узле выполните:
</p>

<div style="background-color:#ffffff;border:1px solid #dfe1e5;color:#333333;font-size:14px;padding:0px;">
	<div style="color:#333333;font-size:14px;padding:0px;text-align:left;">
		<div style="padding:0px;">
			<div style="background-color:#ffffff;font-size:1em;padding:0px;">
				<table border="0" cellpadding="0" cellspacing="0" style="border-collapse:collapse;border-spacing:0px;border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
					<tbody style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
						<tr style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
							<td style="border:0px;font-size:14px;padding:0px 0px 0px 15px;text-align:left;vertical-align:baseline;">
								<div style="border:0px;font-size:14px;padding:0px 0px 15px 0em;text-align:left;vertical-align:baseline;" title="Hint: double-click to select code">
									<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
										<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">apt-settings-manager set --merge /configuration/preprocessor<span> </span></code><code style="border:0px;color:#003366;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">'{"ksn": {"non_dl_formats": ["GeneralHtml", "GeneralTxt", "ExecutableJs", "ImageGif", "ImageJpeg", "ImagePng", "ArchiveCab"], "request_threads": 4, "timeout": "PT1.5S"}}'</code>
									</div>
								</div>
							</td>
						</tr>
					</tbody>
				</table>
			</div>
		</div>
	</div>
</div>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	           <em><span> </span>* PT1.5S означает 1,5 секунды, не нужно менять этот параметр</em>
</p>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	          Затем увеличьте значение "errors_increase_threshold": 100 (нужно проверить журнал отладки ksn_proxy, чтобы понять, сколько ошибок KSN-соединения у вас есть, и настроить этот параметр соответствующим образом)
</p>

<div style="background-color:#ffffff;border:1px solid #dfe1e5;color:#333333;font-size:14px;padding:0px;">
	<div style="color:#333333;font-size:14px;padding:0px;text-align:left;">
		<div style="padding:0px;">
			<div style="background-color:#ffffff;font-size:1em;padding:0px;">
				<table border="0" cellpadding="0" cellspacing="0" style="border-collapse:collapse;border-spacing:0px;border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
					<tbody style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
						<tr style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
							<td style="border:0px;font-size:14px;padding:0px 0px 0px 15px;text-align:left;vertical-align:baseline;">
								<div style="border:0px;font-size:14px;padding:0px 0px 15px 0em;text-align:left;vertical-align:baseline;" title="Hint: double-click to select code">
									<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
										<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">apt-settings-manager set --merge /configuration/monitoring_prometheus<span> </span></code><code style="border:0px;color:#003366;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">'{"ksn_proxy": {"errors_increase_threshold": 100, "errors_window_period": "10m", "scraping_alert_for_interval": "1m", "scraping_evaluation_interval": "30s"}}'</code><br />
										<span>         Можно сохранить это изменение следующим образом:</span>
									</div>
								</div>
							</td>
						</tr>
					</tbody>
				</table>
			</div>
		</div>
	</div>
</div>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	<span>              vim /etc/opt/kaspersky/apt-swarm/swarm_config.json</span>
</p>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	 "ksn": {
</p>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	                "non_dl_formats": [<a href="https://confluence.kaspersky.com/pages/editpage.action?pageId=1133967796" rel="external nofollow" style="background-color:transparent;color:#265951;"><span> </span><span style="border:none;font-size:0px;padding:0px;text-align:left;vertical-align:text-bottom;">Numbered list</span></a>
</p>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	                    "GeneralHtml",
</p>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	                    "GeneralTxt",
</p>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	                    "ExecutableJs",
</p>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	                    "ImageGif",
</p>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	                    "ImageJpeg",
</p>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	                    "ImagePng",
</p>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	                    "ArchiveCab"
</p>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	                ],
</p>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	                "request_threads": 4,
</p>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	                "timeout": "PT0.5S" <span> </span><strong>&lt;&lt;&lt;&lt;&lt; 1.5S</strong>
</p>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	           <u>Find</u>
</p>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	"ksn_proxy": {
</p>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	                    "errors_increase_threshold": 2,<span> </span><strong>&lt;&lt;&lt;&lt;&lt; 100</strong>
</p>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	                    "errors_window_period": "10m",
</p>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	                    "scraping_alert_for_interval": "1m",
</p>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	                    "scraping_evaluation_interval": "30s"
</p>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	 
</p>

<h3 style="background-color:#ffffff;color:#000000;font-size:16px;padding:0px;">
	KATA 5.0/5.1
</h3>

<ul style="background-color:#ffffff;color:#172b4d;font-size:14px;">
	<li>
		<p style="padding:0px;">
			Под root в центральном узле выполните:
		</p>

		<div style="background-color:#ffffff;border:1px solid #dfe1e5;color:#333333;padding:0px;">
			<div style="color:#333333;font-size:14px;padding:0px;text-align:left;">
				<div style="padding:0px;">
					<div style="background-color:#ffffff;font-size:1em;padding:0px;">
						<table border="0" cellpadding="0" cellspacing="0" style="border-collapse:collapse;border-spacing:0px;border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
							<tbody style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
								<tr style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
									<td style="border:0px;font-size:14px;padding:0px 0px 0px 15px;text-align:left;vertical-align:baseline;">
										<div style="border:0px;font-size:14px;padding:0px 0px 15px 0em;text-align:left;vertical-align:baseline;" title="Hint: double-click to select code">
											<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
												<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">console-settings-updater get /kata/configuration/product/monitoring_prometheus | python3 -m json.tool &gt; /tmp/monitoring_prometheus</code>
											</div>
										</div>
									</td>
								</tr>
							</tbody>
						</table>
					</div>
				</div>
			</div>
		</div>
	</li>
	<li>
		Внесите изменения в /tmp/monitoring_prometheus (с помощью vim или nano), найдя следующий блок
	</li>
</ul>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;text-align:left;">
	"ksn_proxy": {<br />
	            "errors_increase_threshold": 100,<span> </span><span style="color:#339966;">&lt;&lt;&lt;&lt;&lt;&lt; 100 вместо 2</span>
</p>

<ul style="background-color:#ffffff;color:#172b4d;font-size:14px;">
	<li>
		Сохраните файл (ESC:wq!)
	</li>
	<li>
		<div style="background-color:#ffffff;border:1px solid #dfe1e5;color:#333333;padding:0px;">
			<div style="color:#333333;font-size:14px;padding:0px;text-align:left;">
				<div style="padding:0px;">
					<div style="background-color:#ffffff;font-size:1em;padding:0px;">
						<table border="0" cellpadding="0" cellspacing="0" style="border-collapse:collapse;border-spacing:0px;border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
							<tbody style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
								<tr style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
									<td style="border:0px;font-size:14px;padding:0px 0px 0px 15px;text-align:left;vertical-align:baseline;">
										<div style="border:0px;font-size:14px;padding:0px 0px 15px 0em;text-align:left;vertical-align:baseline;" title="Hint: double-click to select code">
											<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
												<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">console-settings-updater set /kata/configuration/product/monitoring_prometheus @/tmp/monitoring_prometheus</code>
											</div>
										</div>
									</td>
								</tr>
							</tbody>
						</table>
					</div>
				</div>
			</div>
		</div>
	</li>
</ul>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	Если значение 100 не помогает, вы можете увеличить его до 150-200.
</p>
]]></description><guid isPermaLink="false">37666</guid><pubDate>Sun, 03 Dec 2023 17:32:08 +0000</pubDate></item><item><title>&#x41A;&#x430;&#x43A; &#x443;&#x437;&#x43D;&#x430;&#x442;&#x44C; &#x43F;&#x43E;&#x441;&#x43B;&#x435;&#x434;&#x43D;&#x435;&#x435; &#x432;&#x440;&#x435;&#x43C;&#x44F; &#x43E;&#x431;&#x43D;&#x43E;&#x432;&#x43B;&#x435;&#x43D;&#x438;&#x44F; &#x431;&#x430;&#x437; &#x441;&#x435;&#x43D;&#x441;&#x43E;&#x440;&#x43E;&#x432; [KATA/KEDRE]</title><link>https://forum.kaspersky.com/topic/%D0%BA%D0%B0%D0%BA-%D1%83%D0%B7%D0%BD%D0%B0%D1%82%D1%8C-%D0%BF%D0%BE%D1%81%D0%BB%D0%B5%D0%B4%D0%BD%D0%B5%D0%B5-%D0%B2%D1%80%D0%B5%D0%BC%D1%8F-%D0%BE%D0%B1%D0%BD%D0%BE%D0%B2%D0%BB%D0%B5%D0%BD%D0%B8%D1%8F-%D0%B1%D0%B0%D0%B7-%D1%81%D0%B5%D0%BD%D1%81%D0%BE%D1%80%D0%BE%D0%B2-katakedre-37663/</link><description><![CDATA[<h2 style="background-color:#ffffff;border-bottom-color:#7eff33;color:#000000;font-size:20px;padding:0px;">
	<strong style="background-color:#ffffff;color:#444444;font-size:14px;"><span style="font-size:14px;"><a href="https://forum.kaspersky.com/topic/%D0%B4%D0%B8%D1%81%D0%BA%D0%BB%D0%B5%D0%B9%D0%BC%D0%B5%D1%80-%D0%BE%D0%B1%D1%8F%D0%B7%D0%B0%D1%82%D0%B5%D0%BB%D1%8C%D0%BD%D0%BE-%D0%BA-%D0%BF%D1%80%D0%BE%D1%87%D1%82%D0%B5%D0%BD%D0%B8%D1%8E-%D0%BF%D0%B5%D1%80%D0%B5%D0%B4-%D0%B8%D1%81%D0%BF%D0%BE%D0%BB%D1%8C%D0%B7%D0%BE%D0%B2%D0%B0%D0%BD%D0%B8%D0%B5%D0%BC-%D0%BC%D0%B0%D1%82%D0%B5%D1%80%D0%B8%D0%B0%D0%BB%D0%BE%D0%B2-%D0%B1%D0%B0%D0%B7%D1%8B-%D0%B7%D0%BD%D0%B0%D0%BD%D0%B8%D0%B9-%D1%84%D0%BE%D1%80%D1%83%D0%BC%D0%B0-36969/#comment-148890" rel="" style="background-color:transparent;color:#00a88e;"><span style="color:#e74c3c;">Дисклеймер. Обязательно к прочтению перед использованием материалов базы знаний Форума.</span></a></span></strong>
</h2>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	У сенсоров KATA есть файл aptsn.stt, который содержит время обновления.
</p>

<div style="background-color:#ffffff;border:1px solid #dfe1e5;color:#333333;font-size:14px;padding:0px;">
	<div style="color:#333333;font-size:14px;padding:0px;text-align:left;">
		<div style="padding:0px;">
			<div style="background-color:#ffffff;font-size:1em;padding:0px;">
				<table border="0" cellpadding="0" cellspacing="0" style="border-collapse:collapse;border-spacing:0px;border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
					<tbody style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
						<tr style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
							<td style="border:0px;font-size:14px;padding:0px 0px 0px 15px;text-align:left;vertical-align:baseline;">
								<div style="border:0px;font-size:14px;padding:0px 0px 15px 0em;text-align:left;vertical-align:baseline;" title="Hint: double-click to select code">
									<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
										<code style="border:0px;color:#ff1493;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">echo</code><span> </span><code style="border:0px;color:#003366;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">"$(cd /; find / -name aptsn.stt 2&gt;/dev/null | grep -v "</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">bases_default</code><code style="border:0px;color:#003366;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">" | while read line; do cat "</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">$line</code><code style="border:0px;color:#003366;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">"; done | sed 's/;//' | sort | uniq)"</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">;<span> </span></code><code style="border:0px;color:#ff1493;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">echo</code><span> </span><code style="border:0px;color:#003366;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">"year-month-day-hour-minute"</code>
									</div>
								</div>
							</td>
						</tr>
					</tbody>
				</table>
			</div>
		</div>
	</div>
</div>
]]></description><guid isPermaLink="false">37663</guid><pubDate>Sun, 03 Dec 2023 16:57:18 +0000</pubDate></item><item><title>&#x418;&#x43D;&#x442;&#x435;&#x433;&#x440;&#x430;&#x446;&#x438;&#x44F; &#x441; MDR: &#x43E;&#x448;&#x438;&#x431;&#x43A;&#x430; "Content size exceeds limit 1048576" [KATA/KEDRE]</title><link>https://forum.kaspersky.com/topic/%D0%B8%D0%BD%D1%82%D0%B5%D0%B3%D1%80%D0%B0%D1%86%D0%B8%D1%8F-%D1%81-mdr-%D0%BE%D1%88%D0%B8%D0%B1%D0%BA%D0%B0-content-size-exceeds-limit-1048576-katakedre-37661/</link><description><![CDATA[<h2 style="background-color:#ffffff;border-bottom-color:#7eff33;color:#000000;font-size:20px;padding:0px;">
	<strong style="background-color:#ffffff;color:#444444;font-size:14px;"><span style="font-size:14px;"><a href="https://forum.kaspersky.com/topic/%D0%B4%D0%B8%D1%81%D0%BA%D0%BB%D0%B5%D0%B9%D0%BC%D0%B5%D1%80-%D0%BE%D0%B1%D1%8F%D0%B7%D0%B0%D1%82%D0%B5%D0%BB%D1%8C%D0%BD%D0%BE-%D0%BA-%D0%BF%D1%80%D0%BE%D1%87%D1%82%D0%B5%D0%BD%D0%B8%D1%8E-%D0%BF%D0%B5%D1%80%D0%B5%D0%B4-%D0%B8%D1%81%D0%BF%D0%BE%D0%BB%D1%8C%D0%B7%D0%BE%D0%B2%D0%B0%D0%BD%D0%B8%D0%B5%D0%BC-%D0%BC%D0%B0%D1%82%D0%B5%D1%80%D0%B8%D0%B0%D0%BB%D0%BE%D0%B2-%D0%B1%D0%B0%D0%B7%D1%8B-%D0%B7%D0%BD%D0%B0%D0%BD%D0%B8%D0%B9-%D1%84%D0%BE%D1%80%D1%83%D0%BC%D0%B0-36969/#comment-148890" rel="" style="background-color:transparent;color:#00a88e;"><span style="color:#e74c3c;">Дисклеймер. Обязательно к прочтению перед использованием материалов базы знаний Форума.</span></a></span></strong>
</h2>

<div style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	<h2 style="border-bottom-color:#7eff33;color:#000000;font-size:20px;padding:0px;">
		Проблема
	</h2>

	<p style="padding:0px;">
		Эта ошибка появляется, когда в KATA WebUI загружаются конфигурационные файлы MDR размером более 1 МБ.
	</p>

	<p style="padding:0px;">
		<span style="color:#ffffff;"><a href="https://support.kaspersky.com/KATA/3.7.2/ru-RU/201839.htm" rel="external nofollow">https://support.kaspersky.com/KATA/3.7.2/ru-RU/201839.htm</a></span>
	</p>

	<p style="padding:0px;">
		<img alt="image.png.248f79fb73bfacdad698696447ab4513.png" class="ipsImage ipsImage_thumbnailed" data-fileid="14926" data-ratio="51.14" style="height:auto;" width="483" data-src="https://forum.kaspersky.com/uploads/monthly_2023_12/image.png.248f79fb73bfacdad698696447ab4513.png" src="https://forum.kaspersky.com/applications/core/interface/js/spacer.png" />
	</p>

	<h2 style="border-bottom-color:#7eff33;color:#000000;font-size:20px;padding:0px;">
		Решение
	</h2>

	<p>
		Увеличьте ограничение на размер файла zip-архива с 1 МБ до 2 МБ:
	</p>

	<ol>
		<li>
			<p style="padding:0px;">
				Станьте root-пользователем:
			</p>

			<div style="background-color:#ffffff;border:1px solid #dfe1e5;color:#333333;padding:0px;">
				<div style="color:#333333;font-size:14px;padding:0px;text-align:left;">
					<div style="padding:0px;">
						<div style="background-color:#ffffff;font-size:1em;padding:0px;">
							<table border="0" cellpadding="0" cellspacing="0" style="border-collapse:collapse;border-spacing:0px;border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
								<tbody style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
									<tr style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
										<td style="border:0px;font-size:14px;padding:0px 0px 0px 15px;text-align:left;vertical-align:baseline;">
											<div style="border:0px;font-size:14px;padding:0px 0px 15px 0em;text-align:left;vertical-align:baseline;" title="Hint: double-click to select code">
												<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
													<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">sudo su</code>
												</div>
											</div>
										</td>
									</tr>
								</tbody>
							</table>
						</div>
					</div>
				</div>
			</div>
		</li>
		<li>
			Откройте файл:  <code style="font-size:1em;">/opt/kaspersky/apt-request-utils/lib/request_utils/zip_checker.py</code>
		</li>
		<li>
			<p style="padding:0px;">
				Найдите следующую строку:
			</p>

			<div style="background-color:#ffffff;border:1px solid #dfe1e5;color:#333333;padding:0px;">
				<div style="color:#333333;font-size:14px;padding:0px;text-align:left;">
					<div style="padding:0px;">
						<div style="background-color:#ffffff;font-size:1em;padding:0px;">
							<table border="0" cellpadding="0" cellspacing="0" style="border-collapse:collapse;border-spacing:0px;border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
								<tbody style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
									<tr style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
										<td style="border:0px;font-size:14px;padding:0px 0px 0px 15px;text-align:left;vertical-align:baseline;">
											<div style="border:0px;font-size:14px;padding:0px 0px 15px 0em;text-align:left;vertical-align:baseline;" title="Hint: double-click to select code">
												<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
													<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">def verify_zip(file_to_check, files=(), max_size=(</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">1024</code><span> </span><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">*<span> </span></code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">1024</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">))</code>
												</div>
											</div>
										</td>
									</tr>
								</tbody>
							</table>
						</div>
					</div>
				</div>
			</div>
		</li>
		<li>
			<p style="padding:0px;">
				Измените значение max_size на (1024 *<span> </span><strong>2048</strong>)
			</p>

			<div style="background-color:#ffffff;border:1px solid #dfe1e5;color:#333333;padding:0px;">
				<div style="color:#333333;font-size:14px;padding:0px;text-align:left;">
					<div style="padding:0px;">
						<div style="background-color:#ffffff;font-size:1em;padding:0px;">
							<table border="0" cellpadding="0" cellspacing="0" style="border-collapse:collapse;border-spacing:0px;border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
								<tbody style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
									<tr style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
										<td style="border:0px;font-size:14px;padding:0px 0px 0px 15px;text-align:left;vertical-align:baseline;">
											<div style="border:0px;font-size:14px;padding:0px 0px 15px 0em;text-align:left;vertical-align:baseline;" title="Hint: double-click to select code">
												<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
													<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">def verify_zip(file_to_check, files=(), max_size=(</code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">1024</code><span> </span><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">*<span> </span></code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">2048</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">))</code>
												</div>
											</div>
										</td>
									</tr>
								</tbody>
							</table>
						</div>
					</div>
				</div>
			</div>
		</li>
		<li>
			Сохраните изменения.
		</li>
		<li>
			<p style="padding:0px;">
				Перезапустите uwsgi:
			</p>

			<div style="background-color:#ffffff;border:1px solid #dfe1e5;color:#333333;padding:0px;">
				<div style="color:#333333;font-size:14px;padding:0px;text-align:left;">
					<div style="padding:0px;">
						<div style="background-color:#ffffff;font-size:1em;padding:0px;">
							<table border="0" cellpadding="0" cellspacing="0" style="border-collapse:collapse;border-spacing:0px;border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
								<tbody style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
									<tr style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
										<td style="border:0px;font-size:14px;padding:0px 0px 0px 15px;text-align:left;vertical-align:baseline;">
											<div style="border:0px;font-size:14px;padding:0px 0px 15px 0em;text-align:left;vertical-align:baseline;" title="Hint: double-click to select code">
												<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
													<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">systemctl restart uwsgi</code>
												</div>
											</div>
										</td>
									</tr>
								</tbody>
							</table>
						</div>
					</div>
				</div>
			</div>
		</li>
		<li>
			Очистите кэш браузера, перезагрузите страницу и проверьте, устранена ли проблема.
		</li>
	</ol>
</div>
]]></description><guid isPermaLink="false">37661</guid><pubDate>Sun, 03 Dec 2023 16:52:40 +0000</pubDate></item><item><title>&#x41D;&#x430;&#x441;&#x442;&#x440;&#x43E;&#x439;&#x43A;&#x430; &#x438;&#x43D;&#x442;&#x435;&#x433;&#x440;&#x430;&#x446;&#x438;&#x438; KATA &#x438; KWTS [KATA/KEDRE]</title><link>https://forum.kaspersky.com/topic/%D0%BD%D0%B0%D1%81%D1%82%D1%80%D0%BE%D0%B9%D0%BA%D0%B0-%D0%B8%D0%BD%D1%82%D0%B5%D0%B3%D1%80%D0%B0%D1%86%D0%B8%D0%B8-kata-%D0%B8-kwts-katakedre-37660/</link><description><![CDATA[<h2 style="background-color:#ffffff;border-bottom-color:#7eff33;color:#000000;font-size:20px;padding:0px;">
	<strong style="background-color:#ffffff;color:#444444;font-size:14px;"><span style="font-size:14px;"><a href="https://forum.kaspersky.com/topic/%D0%B4%D0%B8%D1%81%D0%BA%D0%BB%D0%B5%D0%B9%D0%BC%D0%B5%D1%80-%D0%BE%D0%B1%D1%8F%D0%B7%D0%B0%D1%82%D0%B5%D0%BB%D1%8C%D0%BD%D0%BE-%D0%BA-%D0%BF%D1%80%D0%BE%D1%87%D1%82%D0%B5%D0%BD%D0%B8%D1%8E-%D0%BF%D0%B5%D1%80%D0%B5%D0%B4-%D0%B8%D1%81%D0%BF%D0%BE%D0%BB%D1%8C%D0%B7%D0%BE%D0%B2%D0%B0%D0%BD%D0%B8%D0%B5%D0%BC-%D0%BC%D0%B0%D1%82%D0%B5%D1%80%D0%B8%D0%B0%D0%BB%D0%BE%D0%B2-%D0%B1%D0%B0%D0%B7%D1%8B-%D0%B7%D0%BD%D0%B0%D0%BD%D0%B8%D0%B9-%D1%84%D0%BE%D1%80%D1%83%D0%BC%D0%B0-36969/#comment-148890" rel="" style="background-color:transparent;color:#00a88e;"><span style="color:#e74c3c;">Дисклеймер. Обязательно к прочтению перед использованием материалов базы знаний Форума.</span></a></span></strong>
</h2>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	<a href="https://support.kaspersky.com/KWTS/6.1/ru-RU/187067.htm" rel="external nofollow">https://support.kaspersky.com/KWTS/6.1/ru-RU/187067.htm</a>
</p>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	Вскоре после настройки вы можете заметить, что на стороне KWTS появилась ошибка отправки объектов в KATA, а дашборды выглядят так:
</p>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	<a class="ipsAttachLink ipsAttachLink_image" href="https://forum.kaspersky.com/uploads/monthly_2023_12/image.png.6a079b57eb9a4d5db8c033147c38962e.png" data-fileid="14924" data-fileext="png" rel=""><img class="ipsImage ipsImage_thumbnailed" data-fileid="14924" data-ratio="29.29" width="700" alt="image.thumb.png.007698556490eaca375d1d6efa1a3475.png" data-src="https://forum.kaspersky.com/uploads/monthly_2023_12/image.thumb.png.007698556490eaca375d1d6efa1a3475.png" src="https://forum.kaspersky.com/applications/core/interface/js/spacer.png" /></a><a class="ipsAttachLink ipsAttachLink_image" href="https://forum.kaspersky.com/uploads/monthly_2023_12/image.png.26ca1854d06a957cf8ea511a655fbe8c.png" data-fileid="14925" data-fileext="png" rel=""><img class="ipsImage ipsImage_thumbnailed" data-fileid="14925" data-ratio="31.71" width="700" alt="image.thumb.png.a880deede7fb4e92aaefddb8643bfbe6.png" data-src="https://forum.kaspersky.com/uploads/monthly_2023_12/image.thumb.png.a880deede7fb4e92aaefddb8643bfbe6.png" src="https://forum.kaspersky.com/applications/core/interface/js/spacer.png" /></a>
</p>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	 
</p>

<h2 style="background-color:#ffffff;border-bottom-color:#7eff33;color:#000000;font-size:20px;padding:0px;">
	Решение
</h2>

<div style="background-color:#ffffff;border:1px solid #aab8c6;color:#333333;font-size:14px;padding:10px 10px 10px 36px;">
	<div style="padding:0px;">
		Необходимым условием для успешной интеграции с KWTS является версия KATA 3.6.1.752 или выше.
	</div>
</div>

<h4 style="background-color:#ffffff;color:#000000;font-size:14px;padding:0px;">
	KATA
</h4>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	Чтобы очистить задачи, застрявшие в состоянии обработки, выполните следующие действия:
</p>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	1) Найдите KWTS ID:
</p>

<div style="background-color:#ffffff;border:1px solid #dfe1e5;color:#333333;font-size:14px;padding:0px;">
	<div style="color:#333333;font-size:14px;padding:0px;text-align:left;">
		<div style="padding:0px;">
			<div style="background-color:#ffffff;font-size:1em;padding:0px;">
				<table border="0" cellpadding="0" cellspacing="0" style="border-collapse:collapse;border-spacing:0px;border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
					<tbody style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
						<tr style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
							<td style="border:0px;font-size:14px;padding:0px 0px 0px 15px;text-align:left;vertical-align:baseline;">
								<div style="border:0px;font-size:14px;padding:0px 0px 15px 0em;text-align:left;vertical-align:baseline;" title="Hint: double-click to select code">
									<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
										<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">sudo -u kluser psql antiapt -c<span> </span></code><code style="border:0px;color:#003366;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">"select id, sensor_type, sensor_name, ip from lms.client;"</code>
									</div>
								</div>
							</td>
						</tr>
					</tbody>
				</table>
			</div>
		</div>
	</div>
</div>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	На KATA4:
</p>

<div style="background-color:#ffffff;border:1px solid #dfe1e5;color:#333333;font-size:14px;padding:0px;">
	<div style="color:#333333;font-size:14px;padding:0px;text-align:left;">
		<div style="padding:0px;">
			<div style="background-color:#ffffff;font-size:1em;padding:0px;">
				<table border="0" cellpadding="0" cellspacing="0" style="border-collapse:collapse;border-spacing:0px;border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
					<tbody style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
						<tr style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
							<td style="border:0px;font-size:14px;padding:0px 0px 0px 15px;text-align:left;vertical-align:baseline;">
								<div style="border:0px;font-size:14px;padding:0px 0px 15px 0em;text-align:left;vertical-align:baseline;" title="Hint: double-click to select code">
									<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
										<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">docker exec -it `docker ps | grep kedr_database| awk<span> </span></code><code style="border:0px;color:#003366;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">'{print $1}'</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">` psql -U kluser antiapt -c<span> </span></code><code style="border:0px;color:#003366;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">"select id, sensor_type, sensor_name, ip from lms.client;"</code>
									</div>
								</div>
							</td>
						</tr>
					</tbody>
				</table>
			</div>
		</div>
	</div>
</div>

<p>
	Имя и IP KWTS будут такими же, как в разделе Внешние системы в веб-интерфейсе администратора.
</p>

<p>
	Затем очистите задачи, которые могут застрять в "состоянии обработки":
</p>

<div style="background-color:#ffffff;border:1px solid #dfe1e5;color:#333333;font-size:14px;padding:0px;">
	<div style="color:#333333;font-size:14px;padding:0px;text-align:left;">
		<div style="padding:0px;">
			<div style="background-color:#ffffff;font-size:1em;padding:0px;">
				<table border="0" cellpadding="0" cellspacing="0" style="border-collapse:collapse;border-spacing:0px;border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
					<tbody style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
						<tr style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
							<td style="border:0px;font-size:14px;padding:0px 0px 0px 15px;text-align:left;vertical-align:baseline;">
								<div style="border:0px;font-size:14px;padding:0px 0px 15px 0em;text-align:left;vertical-align:baseline;" title="Hint: double-click to select code">
									<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
										<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">sudo -u kluser psql antiapt -c<span> </span></code><code style="border:0px;color:#003366;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">"update lms.task set state = 'error', has_error = True where client_id = &lt;KWTS ID&gt; and state = 'processing' and update_time &lt; now() - interval '1 hour';"</code>
									</div>
								</div>
							</td>
						</tr>
					</tbody>
				</table>
			</div>
		</div>
	</div>
</div>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	На KATA4:
</p>

<div style="background-color:#ffffff;border:1px solid #dfe1e5;color:#333333;font-size:14px;padding:0px;">
	<div style="color:#333333;font-size:14px;padding:0px;text-align:left;">
		<div style="padding:0px;">
			<div style="background-color:#ffffff;font-size:1em;padding:0px;">
				<table border="0" cellpadding="0" cellspacing="0" style="border-collapse:collapse;border-spacing:0px;border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
					<tbody style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
						<tr style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
							<td style="border:0px;font-size:14px;padding:0px 0px 0px 15px;text-align:left;vertical-align:baseline;">
								<div style="border:0px;font-size:14px;padding:0px 0px 15px 0em;text-align:left;vertical-align:baseline;" title="Hint: double-click to select code">
									<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
										<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">docker exec -it `docker ps | grep kedr_database| awk<span> </span></code><code style="border:0px;color:#003366;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">'{print $1}'</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">` psql -U kluser antiapt -c<span> </span></code><code style="border:0px;color:#003366;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">"update lms.task set state = 'error', has_error = True where client_id = &lt;KWTS ID&gt; and state = 'processing' and update_time &lt; now() - interval '1 hour';"</code>
									</div>
								</div>
							</td>
						</tr>
					</tbody>
				</table>
			</div>
		</div>
	</div>
</div>

<p>
	Эта команда безопасна для выполнения, она не причинит вреда, даже если нет никаких застрявших задач.
</p>

<p>
	Чтобы просмотреть все активные задачи из KSMG/KLMS/KWTS/других внешних систем, не изменяя их состояния, выполните команду:
</p>

<div style="background-color:#ffffff;border:1px solid #dfe1e5;color:#333333;font-size:14px;padding:0px;">
	<div style="color:#333333;font-size:14px;padding:0px;text-align:left;">
		<div style="padding:0px;">
			<div style="background-color:#ffffff;font-size:1em;padding:0px;">
				<table border="0" cellpadding="0" cellspacing="0" style="border-collapse:collapse;border-spacing:0px;border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
					<tbody style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
						<tr style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
							<td style="border:0px;font-size:14px;padding:0px 0px 0px 15px;text-align:left;vertical-align:baseline;">
								<div style="border:0px;font-size:14px;padding:0px 0px 15px 0em;text-align:left;vertical-align:baseline;" title="Hint: double-click to select code">
									<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
										<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">docker exec -it `docker ps | grep kedr_database| awk<span> </span></code><code style="border:0px;color:#003366;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">'{print $1}'</code><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">` psql -U kluser antiapt -c<span> </span></code><code style="border:0px;color:#003366;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">"select count(*) from lms.task where client_id=&lt;KSMG ID&gt;;"</code>
									</div>
								</div>
							</td>
						</tr>
					</tbody>
				</table>
			</div>
		</div>
	</div>
</div>

<div style="background-color:#ffffff;border:1px solid #aab8c6;color:#333333;font-size:14px;padding:10px 10px 10px 36px;">
	<div style="padding:0px;">
		<p style="padding:0px;">
			Две приведенные выше команды можно использовать для удаления застрявших в обработке задач и из других типов внешних систем.
		</p>
	</div>
</div>

<h4 style="background-color:#ffffff;color:#000000;font-size:14px;padding:0px;">
	KWTS
</h4>

<p>
	На стороне KWTS важно исключить определенные типы объектов из проверки в KATA:
</p>

<p>
	В файле /var/opt/kaspersky/kwts/kata-filters.json удалите строки, содержащие ключевые слова:
</p>

<div style="background-color:#ffffff;border:1px solid #dfe1e5;color:#333333;font-size:14px;padding:0px;">
	<div style="color:#333333;font-size:14px;padding:0px;text-align:left;">
		<div style="padding:0px;">
			<div style="background-color:#ffffff;font-size:1em;padding:0px;">
				<table border="0" cellpadding="0" cellspacing="0" style="border-collapse:collapse;border-spacing:0px;border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
					<tbody style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
						<tr style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
							<td style="border:0px;font-size:14px;padding:0px 0px 0px 15px;text-align:left;vertical-align:baseline;">
								<div style="border:0px;font-size:14px;padding:0px 0px 15px 0em;text-align:left;vertical-align:baseline;" title="Hint: double-click to select code">
									<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
										<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">ArchiveGzip</code>
									</div>

									<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
										 
									</div>

									<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
										<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">ArchiveCab</code>
									</div>

									<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
										 
									</div>

									<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
										<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">ExecutableJs</code>
									</div>
								</div>
							</td>
						</tr>
					</tbody>
				</table>
			</div>
		</div>
	</div>
</div>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	После внесения изменений перезапустите службу KWTS:
</p>

<div style="background-color:#ffffff;border:1px solid #dfe1e5;color:#333333;font-size:14px;padding:0px;">
	<div style="color:#333333;font-size:14px;padding:0px;text-align:left;">
		<div style="padding:0px;">
			<div style="background-color:#ffffff;font-size:1em;padding:0px;">
				<table border="0" cellpadding="0" cellspacing="0" style="border-collapse:collapse;border-spacing:0px;border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
					<tbody style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
						<tr style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
							<td style="border:0px;font-size:14px;padding:0px 0px 0px 15px;text-align:left;vertical-align:baseline;">
								<div style="border:0px;font-size:14px;padding:0px 0px 15px 0em;text-align:left;vertical-align:baseline;" title="Hint: double-click to select code">
									<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
										<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">systemctl restarts kwts</code>
									</div>
								</div>
							</td>
						</tr>
					</tbody>
				</table>
			</div>
		</div>
	</div>
</div>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	После этих изменений интеграция KWTS и KATA будут работать нормально.
</p>
]]></description><guid isPermaLink="false">37660</guid><pubDate>Sun, 03 Dec 2023 16:31:49 +0000</pubDate></item><item><title>&#x41A;&#x430;&#x43A; &#x43F;&#x440;&#x438;&#x43D;&#x443;&#x434;&#x438;&#x442;&#x435;&#x43B;&#x44C;&#x43D;&#x43E; &#x437;&#x430;&#x43F;&#x443;&#x441;&#x442;&#x438;&#x442;&#x44C; &#x43F;&#x440;&#x43E;&#x432;&#x435;&#x440;&#x43A;&#x443; KATA Sandbox [KATA/KEDRE]</title><link>https://forum.kaspersky.com/topic/%D0%BA%D0%B0%D0%BA-%D0%BF%D1%80%D0%B8%D0%BD%D1%83%D0%B4%D0%B8%D1%82%D0%B5%D0%BB%D1%8C%D0%BD%D0%BE-%D0%B7%D0%B0%D0%BF%D1%83%D1%81%D1%82%D0%B8%D1%82%D1%8C-%D0%BF%D1%80%D0%BE%D0%B2%D0%B5%D1%80%D0%BA%D1%83-kata-sandbox-katakedre-36979/</link><description><![CDATA[<p>
	<strong style="background-color:#ffffff;color:#444444;font-size:14px;"><span style="font-size:14px;"><a href="https://forum.kaspersky.com/topic/%D0%B4%D0%B8%D1%81%D0%BA%D0%BB%D0%B5%D0%B9%D0%BC%D0%B5%D1%80-%D0%BE%D0%B1%D1%8F%D0%B7%D0%B0%D1%82%D0%B5%D0%BB%D1%8C%D0%BD%D0%BE-%D0%BA-%D0%BF%D1%80%D0%BE%D1%87%D1%82%D0%B5%D0%BD%D0%B8%D1%8E-%D0%BF%D0%B5%D1%80%D0%B5%D0%B4-%D0%B8%D1%81%D0%BF%D0%BE%D0%BB%D1%8C%D0%B7%D0%BE%D0%B2%D0%B0%D0%BD%D0%B8%D0%B5%D0%BC-%D0%BC%D0%B0%D1%82%D0%B5%D1%80%D0%B8%D0%B0%D0%BB%D0%BE%D0%B2-%D0%B1%D0%B0%D0%B7%D1%8B-%D0%B7%D0%BD%D0%B0%D0%BD%D0%B8%D0%B9-%D1%84%D0%BE%D1%80%D1%83%D0%BC%D0%B0-36969/#comment-148890" rel="" style="background-color:transparent;color:#00a88e;"><span style="color:#e74c3c;">Дисклеймер. Обязательно к прочтению перед использованием материалов базы знаний Форума.</span></a></span></strong>
</p>

<div style="background-color:#ffffff;border:1px solid #aab8c6;color:#333333;font-size:14px;padding:10px 10px 10px 36px;">
	<div style="padding:0px;">
		<p style="padding:0px;">
			KATA 3.7.2
		</p>
	</div>
</div>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	Вы можете принудительно запустить проверку Sandbox.
</p>

<h2 style="background-color:#ffffff;border-bottom-color:#7eff33;color:#000000;font-size:20px;padding:0px;">
	Пошаговая инструкция
</h2>

<ol style="background-color:#ffffff;color:#172b4d;font-size:14px;">
	<li>
		Подключитесь к серверу Sandbox по ssh.
	</li>
	<li>
		<p style="padding:0px;">
			<code style="font-size:1em;"><font face="Inter, -apple-system, system-ui, Segoe UI, Roboto, Helvetica, Arial, sans-serif, Apple Color Emoji, Segoe UI Emoji, Segoe UI Symbol">Чтобы запустить checker, сначала нужно удалить файлы в </font>/var/tmp/sbtest</code>:
		</p>

		<div style="background-color:#ffffff;border:1px solid #dfe1e5;color:#333333;padding:0px;">
			<div style="color:#333333;font-size:14px;padding:0px;text-align:left;">
				<div style="padding:0px;">
					<div style="background-color:#ffffff;font-size:1em;padding:0px;">
						<table border="0" cellpadding="0" cellspacing="0" style="border-collapse:collapse;border-spacing:0px;border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
							<tbody style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
								<tr style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
									<td style="border:0px;font-size:14px;padding:0px 0px 0px 15px;text-align:left;vertical-align:baseline;">
										<div style="border:0px;font-size:14px;padding:0px 0px 15px 0em;text-align:left;vertical-align:baseline;" title="Hint: double-click to select code">
											<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
												<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">rm /var/tmp/sbtest</code>
											</div>
										</div>
									</td>
								</tr>
							</tbody>
						</table>
					</div>
				</div>
			</div>
		</div>
	</li>
	<li>
		<p style="padding:0px;">
			Запустите checker:
		</p>

		<div style="background-color:#ffffff;border:1px solid #dfe1e5;color:#333333;padding:0px;">
			<div style="color:#333333;font-size:14px;padding:0px;text-align:left;">
				<div style="padding:0px;">
					<div style="background-color:#ffffff;font-size:1em;padding:0px;">
						<table border="0" cellpadding="0" cellspacing="0" style="border-collapse:collapse;border-spacing:0px;border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
							<tbody style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
								<tr style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
									<td style="border:0px;font-size:14px;padding:0px 0px 0px 15px;text-align:left;vertical-align:baseline;">
										<div style="border:0px;font-size:14px;padding:0px 0px 15px 0em;text-align:left;vertical-align:baseline;" title="Hint: double-click to select code">
											<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
												<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">/bin/su -c<span> </span></code><code style="border:0px;color:#003366;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">'exec /opt/kaspersky/sandbox/libexec/utilities/checker.py -l /var/log/kaspersky/sandbox/checker/checker.log'</code><span> </span><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">-s /bin/sh kluser</code>
											</div>
										</div>
									</td>
								</tr>
							</tbody>
						</table>
					</div>
				</div>
			</div>
		</div>
	</li>
	<li>
		<p style="padding:0px;">
			<code style="font-size:1em;"><font face="Inter, -apple-system, system-ui, Segoe UI, Roboto, Helvetica, Arial, sans-serif, Apple Color Emoji, Segoe UI Emoji, Segoe UI Symbol">Затем на Центральном узле запустите скрипт </font>update_sandbox_status.py</code>:
		</p>

		<div style="background-color:#ffffff;border:1px solid #dfe1e5;color:#333333;padding:0px;">
			<div style="color:#333333;font-size:14px;padding:0px;text-align:left;">
				<div style="padding:0px;">
					<div style="background-color:#ffffff;font-size:1em;padding:0px;">
						<table border="0" cellpadding="0" cellspacing="0" style="border-collapse:collapse;border-spacing:0px;border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
							<tbody style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
								<tr style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
									<td style="border:0px;font-size:14px;padding:0px 0px 0px 15px;text-align:left;vertical-align:baseline;">
										<div style="border:0px;font-size:14px;padding:0px 0px 15px 0em;text-align:left;vertical-align:baseline;" title="Hint: double-click to select code">
											<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
												<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">sudo -u kluser flock -w<span> </span></code><code style="border:0px;color:#009900;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">1</code><span> </span><code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">/tmp/health_status_sandbox.lock python -B /opt/kaspersky/apt-base/libexec/health_status/update_sandbox_status.py</code>
											</div>
										</div>
									</td>
								</tr>
							</tbody>
						</table>
					</div>
				</div>
			</div>
		</div>

		<p style="padding:0px;">
			 
		</p>
	</li>
</ol>

<div style="background-color:#ffffff;border:1px solid #aab8c6;color:#333333;font-size:14px;padding:10px 10px 10px 36px;">
	<div style="padding:0px;">
		<p style="padding:0px;">
			Для KATA 4+ / 5+
		</p>
	</div>
</div>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	На Центральном узле с правами root выполните:
</p>

<div style="background-color:#ffffff;border:1px solid #dfe1e5;color:#333333;font-size:14px;padding:0px;">
	<div style="color:#333333;font-size:14px;padding:0px;text-align:left;">
		<div style="padding:0px;">
			<div style="background-color:#ffffff;font-size:1em;padding:0px;">
				<table border="0" cellpadding="0" cellspacing="0" style="border-collapse:collapse;border-spacing:0px;border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
					<tbody style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
						<tr style="border:0px;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">
							<td style="border:0px;font-size:14px;padding:0px 0px 0px 15px;text-align:left;vertical-align:baseline;">
								<div style="border:0px;font-size:14px;padding:0px 0px 15px 0em;text-align:left;vertical-align:baseline;" title="Hint: double-click to select code">
									<div style="border:0px;font-size:14px;padding:0px 1em 0px 0em;text-align:left;vertical-align:baseline;">
										<code style="border:0px;color:#000000;font-size:14px;padding:0px;text-align:left;vertical-align:baseline;">docker exec $(docker ps -q --filter name=kata_scanner) supervisorctl start update_sandbox_status</code>
									</div>
								</div>
							</td>
						</tr>
					</tbody>
				</table>
			</div>
		</div>
	</div>
</div>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	После выполнения команды через 10-15 минут файл из папки /var/tmp/sbtest можно отправить в Службу клиентской поддержки Лаборатории Касперского (если требуется).
</p>
]]></description><guid isPermaLink="false">36979</guid><pubDate>Tue, 31 Oct 2023 16:38:08 +0000</pubDate></item><item><title>&#x41C;&#x43E;&#x434;&#x443;&#x43B;&#x438; YARA &#x434;&#x43E;&#x441;&#x442;&#x443;&#x43F;&#x43D;&#x44B;&#x435; &#x43D;&#x430; &#x426;&#x435;&#x43D;&#x442;&#x440;&#x430;&#x43B;&#x44C;&#x43D;&#x43E;&#x43C; &#x443;&#x437;&#x43B;&#x435; KATA [KATA/KEDRE][KATA/KEDRE]</title><link>https://forum.kaspersky.com/topic/%D0%BC%D0%BE%D0%B4%D1%83%D0%BB%D0%B8-yara-%D0%B4%D0%BE%D1%81%D1%82%D1%83%D0%BF%D0%BD%D1%8B%D0%B5-%D0%BD%D0%B0-%D1%86%D0%B5%D0%BD%D1%82%D1%80%D0%B0%D0%BB%D1%8C%D0%BD%D0%BE%D0%BC-%D1%83%D0%B7%D0%BB%D0%B5-kata-katakedrekatakedre-36978/</link><description><![CDATA[<p>
	<strong style="background-color:#ffffff;color:#444444;font-size:14px;"><span style="font-size:14px;"><a href="https://forum.kaspersky.com/topic/%D0%B4%D0%B8%D1%81%D0%BA%D0%BB%D0%B5%D0%B9%D0%BC%D0%B5%D1%80-%D0%BE%D0%B1%D1%8F%D0%B7%D0%B0%D1%82%D0%B5%D0%BB%D1%8C%D0%BD%D0%BE-%D0%BA-%D0%BF%D1%80%D0%BE%D1%87%D1%82%D0%B5%D0%BD%D0%B8%D1%8E-%D0%BF%D0%B5%D1%80%D0%B5%D0%B4-%D0%B8%D1%81%D0%BF%D0%BE%D0%BB%D1%8C%D0%B7%D0%BE%D0%B2%D0%B0%D0%BD%D0%B8%D0%B5%D0%BC-%D0%BC%D0%B0%D1%82%D0%B5%D1%80%D0%B8%D0%B0%D0%BB%D0%BE%D0%B2-%D0%B1%D0%B0%D0%B7%D1%8B-%D0%B7%D0%BD%D0%B0%D0%BD%D0%B8%D0%B9-%D1%84%D0%BE%D1%80%D1%83%D0%BC%D0%B0-36969/#comment-148890" rel="" style="background-color:transparent;color:#00a88e;"><span style="color:#e74c3c;">Дисклеймер. Обязательно к прочтению перед использованием материалов базы знаний Форума.</span></a></span></strong>
</p>

<p>
	Если вы пишете собственные правила YARA на Центральном узле, то вам могут понадобиться доступные модули YARA и версия.
</p>

<p>
	<em>Версия 3.7-3.11</em> в КАТА 3.7.x
</p>

<p>
	<em>Версия 4.10</em> в КАТА 4.1 и КАТА 5.0
</p>

<p>
	Список модулей:
</p>

<ul style="background-color:#ffffff;color:#172b4d;font-size:14px;">
	<li>
		<code style="font-size:1em;"><span>tests</span></code>
	</li>
	<li>
		<code style="font-size:1em;"><span>pe</span></code>
	</li>
	<li>
		<code style="font-size:1em;"><span>elf</span></code>
	</li>
	<li>
		<code style="font-size:1em;"><span>math</span></code>
	</li>
	<li>
		<code style="font-size:1em;"><span>time</span></code>
	</li>
	<li>
		<code style="font-size:1em;"><span>pe_utils</span></code>
	</li>
	<li>
		<code style="font-size:1em;"><span>magic</span></code>
	</li>
	<li>
		<code style="font-size:1em;"><span>hash</span></code>
	</li>
	<li>
		<code style="font-size:1em;">dotnet</code>
	</li>
	<li>
		<code style="font-size:1em;">dex</code>
	</li>
</ul>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	<span>Более подробную информацию о модулях можно найти в <a href="https://yara-documentation-rus.readthedocs.io/en/latest/chapter_3.html" rel="external nofollow">документации YARA.</a></span>
</p>
]]></description><guid isPermaLink="false">36978</guid><pubDate>Tue, 31 Oct 2023 16:13:28 +0000</pubDate></item><item><title>&#x41E;&#x431;&#x43D;&#x430;&#x440;&#x443;&#x436;&#x435;&#x43D;&#x430; &#x443;&#x44F;&#x437;&#x432;&#x438;&#x43C;&#x43E;&#x441;&#x442;&#x44C; CVE-2016-2183 &#x432; &#x426;&#x435;&#x43D;&#x442;&#x440;&#x430;&#x43B;&#x44C;&#x43D;&#x43E;&#x43C; &#x443;&#x437;&#x43B;&#x435; &#x432;&#x435;&#x440;&#x441;&#x438;&#x438; 4.0 [KATA/KEDRE]</title><link>https://forum.kaspersky.com/topic/%D0%BE%D0%B1%D0%BD%D0%B0%D1%80%D1%83%D0%B6%D0%B5%D0%BD%D0%B0-%D1%83%D1%8F%D0%B7%D0%B2%D0%B8%D0%BC%D0%BE%D1%81%D1%82%D1%8C-cve-2016-2183-%D0%B2-%D1%86%D0%B5%D0%BD%D1%82%D1%80%D0%B0%D0%BB%D1%8C%D0%BD%D0%BE%D0%BC-%D1%83%D0%B7%D0%BB%D0%B5-%D0%B2%D0%B5%D1%80%D1%81%D0%B8%D0%B8-40-katakedre-36977/</link><description><![CDATA[<p>
	<strong style="background-color:#ffffff;color:#444444;font-size:14px;"><span style="font-size:14px;"><a href="https://forum.kaspersky.com/topic/%D0%B4%D0%B8%D1%81%D0%BA%D0%BB%D0%B5%D0%B9%D0%BC%D0%B5%D1%80-%D0%BE%D0%B1%D1%8F%D0%B7%D0%B0%D1%82%D0%B5%D0%BB%D1%8C%D0%BD%D0%BE-%D0%BA-%D0%BF%D1%80%D0%BE%D1%87%D1%82%D0%B5%D0%BD%D0%B8%D1%8E-%D0%BF%D0%B5%D1%80%D0%B5%D0%B4-%D0%B8%D1%81%D0%BF%D0%BE%D0%BB%D1%8C%D0%B7%D0%BE%D0%B2%D0%B0%D0%BD%D0%B8%D0%B5%D0%BC-%D0%BC%D0%B0%D1%82%D0%B5%D1%80%D0%B8%D0%B0%D0%BB%D0%BE%D0%B2-%D0%B1%D0%B0%D0%B7%D1%8B-%D0%B7%D0%BD%D0%B0%D0%BD%D0%B8%D0%B9-%D1%84%D0%BE%D1%80%D1%83%D0%BC%D0%B0-36969/#comment-148890" rel="" style="background-color:transparent;color:#00a88e;"><span style="color:#e74c3c;">Дисклеймер. Обязательно к прочтению перед использованием материалов базы знаний Форума.</span></a></span></strong>
</p>

<p>
	<span style="background-color:#ffffff;color:#444444;font-size:14px;">Предупреждения об уязвимости CVE-2016-2183 можно получить при сканировании Центрального узла v4.0 со следующими небезопасными наборами шифров:</span>
</p>

<p>
	<span style="background-color:#ffffff;color:#444444;font-size:14px;">TLS 1.2: * TLS_RSA_WITH_3DES_EDE_CBC_SHA</span>
</p>

<p>
	<span style="background-color:#ffffff;color:#444444;font-size:14px;"><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2183" rel="external nofollow">Здесь</a> приведены более подробные сведения о CVE-2016-2183.</span>
</p>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	<b><a href="https://box.kaspersky.com/f/b42fff390299483bbbfc/?dl=1" rel="external nofollow">Решение проблемы</a></b>
</p>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	1) docker load &lt; /path/to/container/nginx_gateway-4.0-pf1
</p>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	2) Измените версию контейнера /etc/opt/kaspersky/apt-swarm/image_versions.json<br />
	    "nginx_gateway": "<a href="http://registry.kata.avp.ru/" rel="external nofollow" style="background-color:transparent;color:#265951;">registry.kata.avp.ru</a>:5000/kaspersky/kata/web/nginx_gateway:aa48c91",
</p>

<p style="background-color:#ffffff;color:#172b4d;font-size:14px;padding:0px;">
	3) Загрузите новый контейнер:<br />
	docker service update kataedr_main_1_nginx_gateway --image "<a href="http://registry.kata.avp.ru/" rel="external nofollow" style="background-color:transparent;color:#265951;">registry.kata.avp.ru</a>:5000/kaspersky/kata/web/nginx_gateway:aa48c91"
</p>
]]></description><guid isPermaLink="false">36977</guid><pubDate>Tue, 31 Oct 2023 16:04:37 +0000</pubDate></item><item><title>&#x41A;&#x430;&#x43A; &#x441;&#x43B;&#x435;&#x434;&#x438;&#x442;&#x44C; &#x437;&#x430; &#x441;&#x43E;&#x441;&#x442;&#x43E;&#x44F;&#x43D;&#x438;&#x435;&#x43C; KATA [KATA/KEDRE]</title><link>https://forum.kaspersky.com/topic/%D0%BA%D0%B0%D0%BA-%D1%81%D0%BB%D0%B5%D0%B4%D0%B8%D1%82%D1%8C-%D0%B7%D0%B0-%D1%81%D0%BE%D1%81%D1%82%D0%BE%D1%8F%D0%BD%D0%B8%D0%B5%D0%BC-kata-katakedre-36976/</link><description><![CDATA[<p>
	<strong style="background-color:#ffffff;color:#444444;font-size:14px;"><span style="font-size:14px;"><a href="https://forum.kaspersky.com/topic/%D0%B4%D0%B8%D1%81%D0%BA%D0%BB%D0%B5%D0%B9%D0%BC%D0%B5%D1%80-%D0%BE%D0%B1%D1%8F%D0%B7%D0%B0%D1%82%D0%B5%D0%BB%D1%8C%D0%BD%D0%BE-%D0%BA-%D0%BF%D1%80%D0%BE%D1%87%D1%82%D0%B5%D0%BD%D0%B8%D1%8E-%D0%BF%D0%B5%D1%80%D0%B5%D0%B4-%D0%B8%D1%81%D0%BF%D0%BE%D0%BB%D1%8C%D0%B7%D0%BE%D0%B2%D0%B0%D0%BD%D0%B8%D0%B5%D0%BC-%D0%BC%D0%B0%D1%82%D0%B5%D1%80%D0%B8%D0%B0%D0%BB%D0%BE%D0%B2-%D0%B1%D0%B0%D0%B7%D1%8B-%D0%B7%D0%BD%D0%B0%D0%BD%D0%B8%D0%B9-%D1%84%D0%BE%D1%80%D1%83%D0%BC%D0%B0-36969/#comment-148890" rel="" style="background-color:transparent;color:#00a88e;"><span style="color:#e74c3c;">Дисклеймер. Обязательно к прочтению перед использованием материалов базы знаний Форума.</span></a></span></strong>
</p>

<p>
	<strong><span style="color:#172b4d;">Как отслеживать состояние KATA, например, использование процессора, жесткого диска, памяти, состояние служб и т.д.?</span></strong>
</p>

<p>
	<span style="color:#172b4d;">Локальный мониторинг работы продукта и состояния компонентов можно осуществлять <a href="https://support.kaspersky.com/KATA/4.1/ru-RU/175014_1.htm" rel="external nofollow">на панели управления KATA.</a> Показатели процессора, памяти и т.п. можно посмотреть с помощью встроенных <a href="https://www.tecmint.com/command-line-tools-to-monitor-linux-performance/" rel="external nofollow">средств Linux.</a> </span>
</p>

<p>
	<span style="color:#172b4d;">Доступны следующие варианты удаленного мониторинга:</span>
</p>

<ol style="background-color:#ffffff;color:#172b4d;font-size:14px;">
	<li>
		<span style="color:#172b4d;">Использование <a href="https://support.kaspersky.com/KATA/4.1/ru-RU/226682.htm" rel="external nofollow">SNMP</a></span>
	</li>
	<li>
		<span style="color:#172b4d;">Интеграция с <a href="https://support.kaspersky.com/KATA/4.1/ru-RU/175283.htm" rel="external nofollow">SIEM</a></span>
	</li>
	<li>
		<span style="color:#172b4d;">Отправка <a href="https://support.kaspersky.com/KATA/4.1/ru-RU/176248.htm" rel="external nofollow">уведомлений</a> о состоянии системы.</span>
	</li>
	<li>
		<span style="color:#172b4d;">Для компонента Sandbox доступна только опция SSL-зондирования:</span>
		<ol>
			<li>
				<code>echo "Q" | </code><span style="font-family:monospace, monospace;font-size:1em;"><code>openssl s_client  -connect sandbox:443</code> </span>
			</li>
		</ol>
	</li>
</ol>
]]></description><guid isPermaLink="false">36976</guid><pubDate>Tue, 31 Oct 2023 15:56:10 +0000</pubDate></item><item><title>&#x414;&#x438;&#x441;&#x43A;&#x43B;&#x435;&#x439;&#x43C;&#x435;&#x440;. &#x41E;&#x431;&#x44F;&#x437;&#x430;&#x442;&#x435;&#x43B;&#x44C;&#x43D;&#x43E; &#x43A; &#x43F;&#x440;&#x43E;&#x447;&#x442;&#x435;&#x43D;&#x438;&#x44E; &#x43F;&#x435;&#x440;&#x435;&#x434; &#x438;&#x441;&#x43F;&#x43E;&#x43B;&#x44C;&#x437;&#x43E;&#x432;&#x430;&#x43D;&#x438;&#x435;&#x43C; &#x43C;&#x430;&#x442;&#x435;&#x440;&#x438;&#x430;&#x43B;&#x43E;&#x432; &#x431;&#x430;&#x437;&#x44B; &#x437;&#x43D;&#x430;&#x43D;&#x438;&#x439; &#x444;&#x43E;&#x440;&#x443;&#x43C;&#x430;.</title><link>https://forum.kaspersky.com/topic/%D0%B4%D0%B8%D1%81%D0%BA%D0%BB%D0%B5%D0%B9%D0%BC%D0%B5%D1%80-%D0%BE%D0%B1%D1%8F%D0%B7%D0%B0%D1%82%D0%B5%D0%BB%D1%8C%D0%BD%D0%BE-%D0%BA-%D0%BF%D1%80%D0%BE%D1%87%D1%82%D0%B5%D0%BD%D0%B8%D1%8E-%D0%BF%D0%B5%D1%80%D0%B5%D0%B4-%D0%B8%D1%81%D0%BF%D0%BE%D0%BB%D1%8C%D0%B7%D0%BE%D0%B2%D0%B0%D0%BD%D0%B8%D0%B5%D0%BC-%D0%BC%D0%B0%D1%82%D0%B5%D1%80%D0%B8%D0%B0%D0%BB%D0%BE%D0%B2-%D0%B1%D0%B0%D0%B7%D1%8B-%D0%B7%D0%BD%D0%B0%D0%BD%D0%B8%D0%B9-%D1%84%D0%BE%D1%80%D1%83%D0%BC%D0%B0-36974/</link><description><![CDATA[<p style="background-color:#ffffff;color:#444444;font-size:14px;">
	Материалы, представленные в разделе Форума "Советы и решения" (База знаний Форума), являются результатом работы сотрудников Службы поддержки клиентов Лаборатории Касперского и участников сообщества Форума. Они размещены здесь для удобства использования, развертывания и настройки продуктов Касперского.
</p>

<p style="background-color:#ffffff;color:#444444;font-size:14px;">
	Пожалуйста, помните, что использование команд или рекомендаций из статей без четкого понимания их назначения может привести к ошибкам или сбоям в работе системы. Обращаем ваше внимание на то, что некоторые из представленных материалов не являются официальными, поэтому в ряде случаев техническая поддержка может отказать в поддержке конкретной неподдерживаемой конфигурации.
</p>

<p style="background-color:#ffffff;color:#444444;font-size:14px;">
	<strong>Также просим обязательно использовать официальную документацию, представленную<span> </span><a href="https://support.kaspersky.com/help/ru#/b2b" rel="external nofollow" style="background-color:transparent;color:#00a88e;">по этой ссылке.</a></strong>
</p>
]]></description><guid isPermaLink="false">36974</guid><pubDate>Tue, 31 Oct 2023 15:42:34 +0000</pubDate></item></channel></rss>
