All Apps and Add-ons

How to connect Kaspersky Security Center 11 to Kaspersky App in Splunk?

saleh911
New Member

I have read several question-answer pages everywhere, kaspersky documentation and all other stuff, but unfortunately no clear - professional level explanation on how to perform it. Even Splunk itself does not provide any documentation about it (last time i checked).

I have:

  1. Kaspersky Security Center 11 - Full license.
  2. Kaspersky App for Splunk - downloaded and installed from Splunk Database.
  3. Splunk Enterprise.

I have done:

1) On Kaspersky Security Center Side - i have configured Event Manager to send CEF events to Splunk, with IP/PORT. I have also selected what to send inside the Policies.
2) I have deployed Kaspersky App into the Splunk by tar archive (general installation way) with all required software(add-on) also installed)

How to configure Splunk part? I know that i have to provide Data input and etc, however whatever i try, Kaspersky App does not show anything. I do not see on web interface any relative configurations for Kaspersky App. Are there?

Am i missing something? It looks like yes. Or maybe this is a os-network issue?

Thanks for support.

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...