Jump to content

KSC 11 integration with AlienVault SIEM


Go to solution Solved by Kavuser10,

Recommended Posts

Hello everybody,

The scenario is like below-

Kaspersky Security Center 11 need to be send logs to Syslog Server then from Syslog server logs need to be sent to AlienVault SIEM.

is the above scenario is a good practice? If the scenario is set like the above then -

what will be the method from KSC11 to Syslog Server and then Syslog Server to SIEM….is that push or something else?

 

Thanks in Advance

@Deadlock4400 

 

Link to comment
Share on other sites

Link to comment
Share on other sites

While the KSC and Alien Vault will be integrated then LOGS fro KSC to SIEM = Push or Pull method will be in action?


Yes. KSC will then send messages over syslog and AlienVault knows then how to process them properly. Without enabling the plugin for KSC logs will show up just as generic text logs.

Link to comment
Share on other sites

  • 2 weeks later...
  • Solution

Hello,

After KSC 11 and Syslog server connection done then will the client machine push the logs through KSC 11 automatically or there should make some work like making tasks on KSC11?

You have to enable syslog in the policy that you have pushed on clients. Open the policy in editor and under Events open the specific events that you want to send and make sure syslog is enabled. See here:

https://help.kaspersky.com/KSC/SP3/en-US/151325.htm 

Link to comment
Share on other sites

  • 4 months later...

Hello @Deadlock4400,

 

Did you get to see the logs in the framework? I have configured the plugin in OSSIM and KSC, I receive the logs in /var/log/kaspersky-sc.log but I cannot see them in the web interface. I have tried all formats (CEF, Syslog, etc.).

Edit: I forgot to say I’m using KSC 11 too.

Edit 2: @Kavuser10 , can you help with this?


Thanks in advance.
Álex

Link to comment
Share on other sites

The exact same problem. Export to SIEM is included in KSC, in the policies which events to export to SIEM are selected, policies are applied on the client. I get the logs in /var/log/kaspersky-sc.log, but I do not see them in the web interface. 
Can anyone help with this issue?
Link to comment
Share on other sites

Please sign in to comment

You will be able to leave a comment after signing in



Sign In Now


×
×
  • Create New...