Jump to content

Which license do I need to send events from KSC to SIEM? [moved]


Recommended Posts

Hello all, I have Kaspersky Security Center 10 installed with a Total Security for Business license (Trial), but it doesn't send any events to my SIEM. My scenario is the same as described in this thread: KASPERSKY EVENTS TO SIEM IBM QRADAR, and the thread linked from there, except that I have a different license (same setup, same event message). I thought this license I have encompassed all features. If not, which license do I need to send events to SIEM from KSC? Is there a different trial license that I can use to test this feature? Thanks in advance.
Link to comment
Share on other sites

Thanks KarDip. I compared my setup with the online tutorial, and everything seems ok (see below). I'm using Apache Metron as the SIEM, and I have Apache NiFi listening on port 9122 and setup to send these events to my SIEM, but KSC doesn't even connect to it. I tested it with netcat to make sure, but no data arrives. KSC shows me an event just like the one in the article I linked (but in portuguese, screencap below). For completeness, my licenses are also pictured below. Is there anything else I can check on my setup to diagnose the issue?
Link to comment
Share on other sites

  • 4 weeks later...

Please sign in to comment

You will be able to leave a comment after signing in



Sign In Now


×
×
  • Create New...