Jump to content

Kaspersky Security Center - SIEM Integration With Sumo Logic


Go to solution Solved by fernando.frogel,

Recommended Posts

fernando.frogel
Posted

We are experiencing issues integrating Kaspersky Security Center (KSC) with our SIEM (Sumo Logic). The logs are not being sent

port 515 and server ip agent sumo logic 192.168.1.223

image.thumb.png.4149368c8c133f19210698c5f377e043.png

Renan Corassa
Posted (edited)

Fernando, how are you?
Wouldn't the default port for collection be 514?
Or did you change it in the Sumo tool?

Edited by Renan Corassa
fernando.frogel
Posted

Regarding your question, yes, the default port for Syslog collection is 514, but the Sumo Logic team confirmed that they changed the collection port to 515 on their end.

Renan Corassa
Posted (edited)

Você pode validar via telnet se o KSC pode alcançar o IP 192.168.1.233 na porta 515.

Edited by Renan Corassa
fernando.frogel
Posted

telnet não responde na porta 515 e nem da 514, somente o ping para o servidor, mais as portas usadas são UDP

Renan Corassa
Posted (edited)

Eu tinha esquecido que o telnet não funciona no protocolo UDP, porque o protocolo não é orientado a conexão, desculpe. O Siem é Cloud ou Local? 

Edited by Renan Corassa
fernando.frogel
Posted

o agente é local 192.168.1.233 e envia para nuvem, o do firewall foi configurado para ele esta funcionando

Renan Corassa
Posted (edited)

Have you entered the logs you intend to send to the SIEM?

Edited by Renan Corassa
fernando.frogel
Posted

nesta janela vc quer dizer

 image.thumb.png.41685e00817fc56e4058e5540f3bb145.png

Renan Corassa
Posted

Yes.

What database does KSC use?

fernando.frogel
Posted

Microsoft SQL Server

Renan Corassa
Posted

Fernando, has the collector already been created in Sumo to receive the KSC logs?

fernando.frogel
Posted

Sim, foi criado para receber os logs pela porta 515

Renan Corassa
Posted

If possible, validate in the KSC OS event viewer whether there is any reference to sending logs to the SIEM.

 

Renan Corassa
Posted

Good Morning. 
If possible, change the Sumo collector to default values (UDP/514) and test.

Posted

Hello,

Please remember: this is the english forum.

Regards

fernando.frogel
Posted (edited)

Sorry, this is resume the issue:

We are experiencing issues integrating Kaspersky Security Center (KSC) with our SIEM (Sumo Logic). The logs from KSC are not being sent to Sumo Logic as expected.

Current Configuration:
SIEM (Sumo Logic) Agent Server IP: 192.168.1.223
Syslog Collection Port: 515/UDP (Confirmed with Sumo Logic team)
Expected Behavior: Logs should be sent from KSC to Sumo Logic via port 515.
Issue Observed: No logs are being transmitted to Sumo Logic.

Additional Information:
We understand that the default Syslog collection port is 514, but the Sumo Logic team has confirmed that they changed the collection port to 515 on their end.
 

Edited by fernando.frogel
  • Solution
fernando.frogel
Posted

To successfully integrate Kaspersky Security Center (KSC) with Sumo Logic, it is necessary to adjust the policies on both workstations and servers to ensure that events are properly forwarded to the SIEM.

Renan Corassa
Posted

In what sense of adjustment? Was there some active component in the policy that prevented shipping?

Please sign in to comment

You will be able to leave a comment after signing in



Sign In Now


×
×
  • Create New...