Jump to content

How to migrate to a clean KSC server while keeping production active?


Recommended Posts

HelloWorld
Posted

Hello everyone,

I’m currently working on a complete redesign of our Kaspersky Security Center (KSC) infrastructure, and I’d like your advice and recommendations to validate the best strategy in my case.

--Current situation
We currently have a single KSC server in production, managing all endpoints (around [insert number of endpoints]).
This server works, but it is overloaded, disorganized, and difficult to maintain, with issues such as:

Multiple duplicate groups, policies, and tasks.

Many endpoints not connected for a long time (obsolete).

Expired license.

Overall unoptimized structure.

Fixing everything live on this server would take a lot of time and could disrupt users.

etc …
--------------------------------------------------------------------------------------------------------------
-- My idea
-----------
To avoid “fixing” the production server live, my idea is:
Deploy a new, clean KSC server (in a pre-production environment), properly licensed and updated to the latest version.
Recreate or import an optimized and organized structure: groups, policies, and tasks.
Test and optimize everything on this new server.
Once everything is ready, switch production over to this new server and retire the old one.

 The challenge I’m facing
 ------------------------
From my research and testing, it seems that an endpoint can only report to one KSC server at a time — meaning I cannot have both servers (old and new) managing the same endpoints in parallel.
This makes it difficult to prepare the new server quietly while keeping endpoints under management by the old server.
---------------------------------------------------------------------------------------------------------------
 My questions
1️⃣ Is this approach (building a clean server and migrating endpoints to it) the recommended best practice?
2️⃣ Is there an official way to “import” only the structure (groups, policies, tasks) from the old server to the new one and then clean it up there?
3️⃣ What are the best practices you recommend to migrate endpoints progressively to the new server without disturbing users?
4️⃣ Are there official tools, scripts, or procedures from Kaspersky to help with this kind of migration (like repointing agents to the new server via GPO or script)?

Sorry for the long post, and thanks in advance for your feedback and advice!
 

Please sign in to comment

You will be able to leave a comment after signing in



Sign In Now


×
×
  • Create New...