All Apps and Add-ons

How to connect Kaspersky Security Center 11 to Kaspersky App in Splunk?

saleh911
New Member

I have read several question-answer pages everywhere, kaspersky documentation and all other stuff, but unfortunately no clear - professional level explanation on how to perform it. Even Splunk itself does not provide any documentation about it (last time i checked).

I have:

  1. Kaspersky Security Center 11 - Full license.
  2. Kaspersky App for Splunk - downloaded and installed from Splunk Database.
  3. Splunk Enterprise.

I have done:

1) On Kaspersky Security Center Side - i have configured Event Manager to send CEF events to Splunk, with IP/PORT. I have also selected what to send inside the Policies.
2) I have deployed Kaspersky App into the Splunk by tar archive (general installation way) with all required software(add-on) also installed)

How to configure Splunk part? I know that i have to provide Data input and etc, however whatever i try, Kaspersky App does not show anything. I do not see on web interface any relative configurations for Kaspersky App. Are there?

Am i missing something? It looks like yes. Or maybe this is a os-network issue?

Thanks for support.

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...