Kaspersky Anti Targeted Attack Platform

Adding active polling job

For devices known to the application, you can add active polling jobs.

Only users with the Senior security officer role can add active polling jobs. Adding active polling jobs is available after adding a license key.

The active polling job is configured using the Wizard. The wizard lets you configure the job step by step. After completing the configuration, you can wait until the scanning begins on schedule or start the job manually.

When adding an active polling job, you can invoke the Configuration Wizard in the following ways:

  • Adding a job with blank settings. To do this:
    1. Select the Assets section.
    2. On the Active polling tab, click Add job.

    The settings of the configuration wizard do not have default values.

  • Adding a job for selected devices. To do this:
    1. Select the Assets section.
    2. On the Devices tab, select the devices for which you want to add an active polling job. You can select no more than 100 devices.
    3. In the toolbar above the devices table, open the Create job drop-down list and select Active polling.

    By default, a list of devices made up of the selected devices is created in the settings of the configuration wizard.

To configure the job in the window of the configuration wizard:

  1. Read the active polling considerations in the warning window, and confirm that you accept the risks associated with using the active polling module.
  2. In the Select devices section of the Wizard, create a list of devices for which you want to perform active polling. Select up to 100 devices.

    You can create a list of devices using the Add to job and Delete from job buttons. To add a device, the application opens a window with the device selection table. You can filter and sort the table to display the devices that you need.

  3. In the Select parameters section of the wizard, select the check boxes for the specific device information that you want to update using active polling. You can also enable risk detection (the Risks check box) and discovery of topology settings for devices (the Topology settings check box).
  4. In the Select methods section of the wizard, do the following:
    1. Select an active polling module.
    2. Select the check boxes for the specific methods that you want to use for getting device information, risk detection, and/or reading topology settings.

      Methods that can be used are grouped by connectors that provide the ability of actively polling devices. The list contains only methods that support getting the selected information. If a connector cannot be used to actively poll the selected devices, the available methods are not displayed for this connector (for example, if the connector is disabled or an address space that does not contain the addresses of the selected devices is selected for the connector).

    3. Configure the methods for each connector as needed. For example, for Polling via SSH, specify a port and a credentials secret.

      If a secret with the required credentials has not been added to the application, you can open a new tab in the browser without closing the Configuration Wizard window, connect to the Server and add the secret, and then use the button in the Configuration Wizard window to refresh the list of secrets.

      We do not recommend using the same secret for active polling of devices on the network because this negatively affects the level of information security.

      Methods that require configuring settings are highlighted in red. To update the settings, click the Setting regulator icon. button to the right of the desired method.

  5. In the Job configuration section of the wizard, configure the rest of the job settings:
    1. Enter a name and description for the job.

      You can use letters, numerals, spaces, and the following special characters: ! @ # № $ % ^ & ( ) [ ] { } / \ : ; , . - _. The name of the job must begin and end with any valid character other than a space.

      The job name must contain no more than 256 characters. The job description must contain no more than 4,096 characters.

    2. To run the job according to a schedule, enable the Run job according to schedule option and configure the schedule settings:
      • In the Frequency drop-down list, select how often to run the job: Hourly, Daily, Weekly, or Monthly.
      • Depending on the selected option, specify the values for the settings to define the precise job start time.

      The application run the job according to the schedule, provided that the previous start of this job has been completed. If by the time a scheduled job is started its previous launch has the Running status, the application skips the run of the scheduled job.

  6. Click Create job or Create and run to close the wizard.

The specified settings are displayed in the job details.