

Commodore
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
2012-10-29
03:03
310 views
Kaspersky event logs
Hi all,
I want to ask some questions if anyone who has collected and done some use cases with Kaspersky event logs before.
- Do we have to change any configuration in Kaspersky Management Interface?
- Althought information such as client hostname is visible in Kaspersky event logs, when events come into ESM, it (client hostname) does not appear in any field.
- Could you share some use cases for Kaspersky? I have created some, but they do not run because of valualess resource data.
Thank you.
Brgds,
Linh.
1 Reply
SchneiderCh

Absent Member.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
2013-03-25
15:48
Hi Linh,
I'm experiencing exactly the same problem with Kaspersky event logs. Information is available in Kaspersky Management, but events in ArcSight are incomplete (Device Address is always 0.0.0.0, Device Hostname is completely missing etc.).
Did you already find a solution for the problem?
Kind regards,
Christoph