Jump to content

KSC Integration SIEM - Data format not configurable


Recommended Posts

Hi,

I need to configure a KSC to send logs to the Elastic SIEM (ELK). The logs must be in CEF format but the "Data Fomart" field cannot be modified. Why? Is it because Kaspersky is in the cloud? It's remain System Log

image(1).thumb.png.7a33f6d6407692f237422972abd64b42.png

 

Guide for KasperskySecurity Center (About exporting events using CEF and LEEF formats (kaspersky.it)) tell me how change data format, guide for Security Center Cloud Console (Configuring Kaspersky Security Center Cloud Console for export of events to a SIEM system) no. Why?

Thanks.

Link to comment
Share on other sites

Please sign in to comment

You will be able to leave a comment after signing in



Sign In Now


×
×
  • Create New...