cancel
Showing results for 
Search instead for 
Did you mean: 

Kaspersky integration issue.

Dear Team,

we are integrated Kaspersky antimalware via SQL pull method and its successfully added. But we are not getting any logs on ESM dashboards.

So someone help us to resolve this issue. Is there any guide to troubleshoot SQL pull method issue?

regards,

kamlakar kadam

11 Replies
Reliable Contributor sssyyy
Reliable Contributor
Report Inappropriate Content
Message 2 of 12

Re: Kaspersky integration issue.

make sure the user account used for SQL pull has dbreader and public rights.

Re: Kaspersky integration issue.

yes user account has full public rights with DBreader

Re: Kaspersky integration issue.

We are experiencing the same issue. Did you resolve it?

Highlighted
sam1
Level 7
Report Inappropriate Content
Message 5 of 12

Re: Kaspersky integration issue.

We are also experiencing the same issue.

Did someone find solution?

 

marceh
Level 7
Report Inappropriate Content
Message 6 of 12

Re: Kaspersky integration issue.

I had the same problem and it was because of the user's permissions in the DB, these permissions are from the schemas, so you enter the BD of the epo then to security, you enter the user's properties for the SIEM and habilias db_datareader (for example, I tmb enable db_datawriter) and I also did it in memership

 

______

I speak Spanish but not very good English, I hope to help you.

mikrotik
Level 11
Report Inappropriate Content
Message 7 of 12

Re: Kaspersky integration issue.

Hello Guys,

I have not seen so far on internet who did this task siccessfully. 

However, do you guys need such thing? Smiley Very Happy

KSC1.png

 

 

 

 

 

 

Hint: Use SQL pull method

Good Luck!

Thank You!

 

Best Regards,

Yours Sincerely,
Syed Irfan Naseer
Reliable Contributor David1111
Reliable Contributor
Report Inappropriate Content
Message 8 of 12

Re: Kaspersky integration issue.

Hi Syed Irfan Naseer.

 

Could you please help me with the integration of the Kaspersky with mcAfee ESM ?!

i know what i need to do in the McAfee, but no idea what to configure in the Kaspersky side.

Could you provide a screenshot of the Kaspersky Settings ?!

 

Thank you very much!!!

best regards

David

mikrotik
Level 11
Report Inappropriate Content
Message 9 of 12

Re: Kaspersky integration issue.

Hi David,

Firstly, Kaspersky Administration Console or KSC nothing has to do with SIEM for integration process.

Secondly, It is only Database of Kaspersky which is integrated with SIEM.

Lastly,  are you sure the account you are using for Pull method has DB access rights of KSC?  if yes then how are you sure?

Thank You!

 

 

Yours Sincerely,
Syed Irfan Naseer
Reliable Contributor David1111
Reliable Contributor
Report Inappropriate Content
Message 10 of 12

Re: Kaspersky integration issue.

Hi Syed Irfan Naseer
first of all, Thanks' on the Quick Response!

i still didn't get from the customer the User Account name and password.

Becuse the IT company that's handeling the Kaspersky dosn't whant to provide me that,
They Claim that they need to send it via Syslog, the problem is i dont get the syslog, besides that it means i will need to write a lot of Parsing REGEX rules..... 😞

It would be very kind of you, if you could provide for me a screenshot of the configurations on the Kaspersky side, then i will be able to get them configure it properlly.

Best Regards.

Thanks' again.

More McAfee Tools to Help You
  • Subscription Service Notification (SNS)
  • How-to: Endpoint Removal Tool
  • Support: Endpoint Security
  • eSupport: Policy Orchestrator