Security Compliance
Kaspersky logs collection in SEM using DB Connector Method
Kaspersky Administration Kit 8 system and application logs are stored on a SQL database defined by the administrator during installation. These include all of the log files from each Kaspersky agent, and they can be collected and monitored with SolarWinds SEM using a SEM Agent on the Kaspersky Administration Kit server.
First published date
Last published date
Overview
These include all of the log files from each Kaspersky agent and they can be collected and monitored with SolarWinds Security Event Manager (formerly Log & Event Manager) using a SEM Agent installed on the Kaspersky Administration Kit server and configuring the Kaspersky Admin or Security Center connector.
Product section
Cause
Resolution
Please note following procedure is applicable for Kaspersky Security Center 11 or 13 and Kaspersky Administration Server Connectors.
Requirements:
- Database Server Host Name: Enter
localhostif your server uses SQL Express. An IP address may also be used. You will need the following information about your Kaspersky Administration Kit database prior to configuring the Kaspersky Aministration Kit tool on the SEM Agent. These items are defined during the Kaspersky Administration Kit installation. Consult with your SQL administrator or Kasperkey Administrator to acquire this information. - Database Name: The default name is
KAV. - Database Server Instance Name: The default name is
KAV_CS_ADMIN_KIT. - Database Server Port:
If you are using MSSQL 2005 or 2008 Standard or Enterprise, the default port is1433.
If you are using SQL Express then complete the following procedure to determine the dynamic port assigned to the KAV database instance:- Open SQL Server Configuration Manager.
- Expand SQL Server your version Network Configuration (32bit).
- Click Protocols for your database server instance name, and then select Action > Properties.
- In the Protocol Name list, click TCP/IP, and then select Action > Properties. The Dynamic Port # is at the bottom of the list.So, for more info please check this MS KB on how to switch to static port on SQL
Note: If TCP/IP is disabled, enable it. This requires that you restart the SQL service.
- Database Server Username and Password: If you are using mixed mode SQL authentication, enter administrator-level credentials for the Kaspersky Administrator Kit server. Note: The login details in connector should match the credentials used to login to the Kaspersky DB and in some cases the SEM agent service must be running with a same or local system account that can authenticate to Kaspersky DB.
- Tool: Kasperky Adminstration Kit / Security Center Connector
To configure logging for a Kaspersky agent, complete the following procedure: You can configure each Kaspersky agent to send specific log data to be stored on the Kaspersky Administration Kit server.
- Open the Kaspersky Administration Kit Console.
- Locate the agent policy you want to configure.
- Click the policy and select Action > Properties.
- Click the Events tab.
- Modify the policy according to your preference.
- If you are finished modifying the policy, click Activate.
Install and Configuring a SEM Agent on the Kaspersky Administration Kit / Security Center Server
- Once this procedure is complete you will begin seeing Alerts from your Kaspersky Administration Kit server in your SEM Console. For additional visibility, create a filter for these alerts. For example:
AnyAlert.ToolAlias = *Kaspersky*, provided you retained the default tool alias when you configured the tool. Install a SolarWinds SEM Agent on the Kaspersky Administration Kit server using the SolarWinds SEM Agent Installer or Remote Agent Installer. - Open the SEM Console, and navigate to Manage > Nodes.
- Find the Kaspersky Administration Kit Agent in the list, click the gear icon next to it, and then click Tools.
- Find the Kaspersky Administration Kit 8 tool/ Security Center Tool depending on what you are running in the list, click the gear icon next to it, and then click New.
- Complete the form using the information gathered above in the Requirements section above.
- Click Save.
- Click the gear icon next to the new tool, and click Start.
- If the tool does not start, verify the tool settings against the SQL server settings.