Kaspersky Anti Targeted Attack Platform

Configuring automatic saving of traffic for system event types

When editing event types, you can enable or disable automatic saving of traffic for events when they are registered. If traffic saving is enabled, the database stores the network packet that caused the registration of the event, as well as the packets before and after the registration of the event that were detected within the network session in which the event was registered. Traffic saving settings determine how many network packets are saved and time limits.

If automatic traffic saving is disabled for an event type, and user-defined settings enabling traffic saving have been configured for this event type, you can download traffic only within a certain time frame after the registration of an event of this type. In this case, the application uses traffic dump files for downloading traffic. These files are stored temporarily and automatically deleted as new traffic arrives. When traffic is downloaded from these files, as many network packets are saved in the database as configured by default when you enable traffic saving for event types.

The application saves traffic in the database only when an event is registered. If the conditions for registering this event recur during the regeneration period, the traffic for that moment is not saved in the database.

You can enable and configure traffic saving for any event types.

If traffic saving is enabled for aggregate events (that is, for system event type 8000000001), the application saves traffic for all nested events when registering an aggregate event. The settings specified for the aggregate event are applied when saving the traffic of nested events. However, traffic saving settings specified directly for the types of events nested in the aggregate event override the settings specified for the aggregate event. That is, traffic for nested events is saved in accordance with the settings specified for the types of these events, and if such settings are not specified, the settings of the aggregating event are used.

To enable and configure traffic saving for an event type:

  1. In the window of the application web interface, select the Settings section, Event types subsection.
  2. In the table of event types, select the type of event that you want to edit.

    The details area appears in the right part of the web interface window.

  3. Click Edit.
  4. Set the Save traffic toggle switch to Enabled.
  5. Configure the saving of traffic from before the event was registered. To do so, specify relevant values in Total packets before event and/or Time to event, ms. Zero means the setting is not applied. If values are specified in both of these fields, the application saves the minimum number of packets that match one of the specified values.
  6. Configure the saving of traffic from after the event was registered. To do so, specify the relevant values in Total packets after event and/or Time after event, ms. Zero means the setting is not applied. If values are specified in both of these fields, the application saves the minimum number of packets that match one of the specified values.

    For some technologies (in particular, Deep Packet Inspection), fewer packets from after registration may be saved in events than configured in traffic saving settings. This is due to the peculiarities of the traffic monitoring technology.

  7. Click Save.