Kaspersky Anti Targeted Attack Platform

Enabling and disabling the recording of information in the activity log

To enable or disable the logging of information about user actions in the Kaspersky Anti Targeted Attack Platform web interface to the activity log:

  1. Select the Logs section, User activity subsection in the application web interface.
  2. Do one of the following:
    • Set the Event logging toggle switch to the Enabled position if you want to enable the logging of information about user actions in the application web interface.
    • Set the Event logging toggle switch to the Disabled position if you want to disable the logging of information about user actions in the application web interface.

      This function is enabled by default.

Information about user actions is recorded in the user_actions.log file, which is stored on the Central Node server in the /data/storage/volumes/siem_proxy/log-user-actions/ directory. By default, records in this file are kept for 90 days, after which they are deleted.

To view the activity log records, you need to download the user_actions.log file.

You can configure the logging of information about user activity in the application web interface to a remote log. The remote log is saved on the server on which a SIEM system is installed. The settings of integration with the SIEM system must be configured to write to the remote log.

In distributed solution mode, information about user actions in the application web interface is recorded in the log of the same server for which the users are managing the web interface. Information about the actions of PCN server users that affect the settings of SCN servers is recorded in the PCN server log.

Users with the Security auditor role can only view the settings for logging information to the activity log.