Kaspersky Next XDR Expert

Configuring Open Single Management Platform for export of events to the KUMA SIEM-system

KUMA allows you to receive and export events from Open Single Management Platform Administration Server to the KUMA

.

Configuring the export and receipt of Open Single Management Platform events proceeds in stages:

  1. Configuring the export of Open Single Management Platform events.
  2. Configuring the KUMA Collector.
  3. Installing the KUMA collector in the network infrastructure.
  4. Verifying receipt of Open Single Management Platform events in the KUMA collector

    You can verify if the events from Open Single Management Platform Administration Server were correctly exported to the KUMA SIEM system by using the KUMA Console to search for related events.

    To display Open Single Management Platform events in CEF format in the table, enter the following search expression:

    SELECT * FROM `events` WHERE DeviceProduct = 'KSC' ORDER BY Timestamp DESC LIMIT 250

In this section

Configuring KUMA collector for collecting Open Single Management Platform events

Installing KUMA collector for collecting Open Single Management Platform events