Kaspersky Anti Targeted Attack Platform

Viewing the table of event types

The event types provided in the application are displayed in the Settings section, Event types subsection of the application web interface.

The table of event types contains system event types. These event types are created by the application during installation and cannot be removed from the list. Event registration technologies implemented in the application use different sets of system event types.

On the basis of some system event types, you can configure user-defined event settings to be used when registering events in certain cases. User-defined settings can be defined for the event type of the External systems technology, code 4000005400, to be used for registering events using the Kaspersky Anti Targeted Attack Platform API NDR.

User-defined settings take precedence when registering events. In absence of user-defined settings, settings configured in the system event types are used.

The following settings are provided for event types:

  • Code – unique number (identifier) of the event type. In the table of event types, the number is displayed together with the event title in the Code and title column. In the table of registered events, the event type ID is displayed in the Event type column.
  • Title – contents of the event title presented as text and/or variables. System event types can use variables specific only to these types of events, or general variables, which can also be used in user-defined settings. In the table of event types, the content of the title is displayed together with the event type number in the Code and title column. In the table of registered events, the text of the title and/or received values of variables are displayed in the Title column.
  • Base score – initial value for calculating the score of the registered event. If an event type can have different base scores, the maximum value is displayed. This setting is displayed in the table of event types.
  • Technology – technology used for event registration. This setting is displayed in the table of event types.
  • Description – additional text that describes the event type. Similarly to the title, can contain variables. This setting is not displayed in the table of event types. You can view the description in the details area of the selected event type. In the table of registered events, the text of the description and/or the resulting values of variables are displayed in the Description column.
  • <Recipient connector name> – name of the connector that the application uses to send events to the third-party system. The application sends to third-party systems only events of types that are configured for sending through the connector. Each connector, through which forwarding of events to third-party systems is configured, is displayed in a separate column of the table of risk types. This setting is not displayed in the details area of the selected event type.
  • Event regeneration period – maximum time after which an event can be registered again. If the conditions for event enrollment are repeated before the specified time period elapses, a new event is not registered but the counter for the number of repeats of the previously registered event is increased and the date and time of the last occurrence of the event is updated. After the end of this period, when the conditions for registering an event recur, the application register a new event of this type. The regeneration period starts counting from the moment of the last registration of an event of this type. For example, if the regeneration period is set to 8 hours, and conditions for registering this event recur two hours after the previous event, a new event is not registered. A new event is registered if the conditions are detected after 8 hours or later. This setting is not displayed in the table of event types. You can view and configure this setting in the details area of the selected event type.

    For registered events, the regeneration period may expire earlier than configured. Repeated registration of an event is allowed earlier than the configured time if the Resolved status is assigned to the event, or if the Central Node computer performing is restarted.

  • Save traffic – this setting enables or disables automatic saving of traffic when an event is registered. This setting is not displayed in the table of event types. You can view and configure this setting in the details area of the selected event type.

    If automatic saving of traffic is disabled, you can manually download traffic for some time after an event of this type is registered. When the application gets a request to download traffic, it searches for network packets in its temporarily generated traffic dump files. If the necessary network packets are found in the traffic dump files, these packets are downloaded (after being saved in the database first).

When viewing the table of event types, you can use the configuration, filtering, searching, and sorting functionality.