Kaspersky Container Security

Viewing and editing SIEM integration settings

To view a SIEM integration:

  1. Open the list of SIEM integrations in the Administration → Integrations → SIEM section.
  2. Click the integration name in the list of integrations.

To edit SIEM integration settings:

  1. In the Administration → Integrations → SIEM section, click the integration name in the list of integrations.
  2. If necessary, in the displayed sidebar, edit the integration parameters as follows:
    1. On the General tab, edit the following required parameters:
      • Name of the SIEM system
      • Protocol for connecting to the SIEM system
      • SIEM system server address
      • SIEM system connection port
      • Categories of events to be exported
    2. If necessary, on the Agent group logs tab, you can edit the list of network node monitoring event types selected for the runtime.
  3. If TCP is used for the connection, click Test connection to see if the connection to the SIEM system is can be established.
  4. Click Save.