Kaspersky Anti Targeted Attack Platform

Viewing user activity audit records

Kaspersky Anti Targeted Attack Platform can save information about actions performed by users of the NDR functionality. Information is saved in the audit log if user activity audit is enabled.

You can view audit records when connecting to the Central Node server using the web interface. If necessary, you can also configure audit records to be sent to third-party systems through connectors.

Only users with the Administrator role can view audit records.

To view audit records:

  1. Connect to the Central Node server using the web interface.
  2. Select the Logs section, Audit subsection.

The table displays audit records corresponding to the specified filtering and search conditions.

Audit record settings are displayed in the following columns of the table:

  • Date and time.

    Date and time when user activity information was recorded.

  • Action.

    Registered action performed by the user.

  • Result.

    Result of the registered action (successful or unsuccessful).

  • User.

    Name of the user that performed the registered action.

  • User node.

    IP address of the node where the registered action was performed.

  • Description.

    Additional information about the registered action.

When viewing the table of audit records, you can use the configuration, filtering, searching, and sorting functionality.