Kaspersky Anti Targeted Attack Platform

Sending events, application messages, and audit records to third-party systems

You can configure the forwarding of events, application messages or audit records (hereinafter also "registered notifications") to a third-party system through connectors. For the connector types named Syslog, SIEM, and Email, the ability to send registered notifications is enabled by default. For the KUMA connector type, the capability to forward registered notifications is available if application modules are installed. When using other connector types that were added to the application, whether this capability is available depends on the settings of these specific connector types.

Registered notifications are configured for each connector individually. When configuring event types, you can select which types of events you want to be forwarded through the connectors. When creating a connector or editing its settings, you can enable or disable the forwarding of all application messages and all audit records through this connector.

Connectors of the Email type allow limiting the amount of transmitted data. For this connector type, you can set the maximum number of email messages about new registered notifications and the maximum number of registered notifications in each message. If the maximum number of email messages already has been sent, another message is sent to recipients to notify them about the limit being exceeded. After that, no new messages are sent until the end of the current day in the time zone of the Central Node server.

Email messages sent through an Email connector are generated separately for each type of registered notifications. That is, different email messages are generated for events, application messages, and audit records.

The contents and order of information about registered notifications that are forwarded through connectors of the Syslog and SIEM types may differ in these systems from the contents and order of information displayed in the Kaspersky Anti Targeted Attack Platform web interface.