cancel
Showing results for 
Search instead for 
Did you mean: 

Kaspersky integration issue.

Dear Team,

we are integrated Kaspersky antimalware via SQL pull method and its successfully added. But we are not getting any logs on ESM dashboards.

So someone help us to resolve this issue. Is there any guide to troubleshoot SQL pull method issue?

regards,

kamlakar kadam

11 Replies
Reliable Contributor sssyyy
Reliable Contributor
Report Inappropriate Content
Message 2 of 12

Re: Kaspersky integration issue.

make sure the user account used for SQL pull has dbreader and public rights.

Re: Kaspersky integration issue.

yes user account has full public rights with DBreader

Re: Kaspersky integration issue.

We are experiencing the same issue. Did you resolve it?

sam1
Level 7
Report Inappropriate Content
Message 5 of 12

Re: Kaspersky integration issue.

We are also experiencing the same issue.

Did someone find solution?

 

marceh
Level 7
Report Inappropriate Content
Message 6 of 12

Re: Kaspersky integration issue.

I had the same problem and it was because of the user's permissions in the DB, these permissions are from the schemas, so you enter the BD of the epo then to security, you enter the user's properties for the SIEM and habilias db_datareader (for example, I tmb enable db_datawriter) and I also did it in memership

 

______

I speak Spanish but not very good English, I hope to help you.

mikrotik
Level 11
Report Inappropriate Content
Message 7 of 12

Re: Kaspersky integration issue.

Hello Guys,

I have not seen so far on internet who did this task siccessfully. 

However, do you guys need such thing? Smiley Very Happy

KSC1.png

 

 

 

 

 

 

Hint: Use SQL pull method

Good Luck!

Thank You!

 

Best Regards,

Yours Sincerely,
Syed Irfan Naseer
Reliable Contributor David1111
Reliable Contributor
Report Inappropriate Content
Message 8 of 12

Re: Kaspersky integration issue.

Hi Syed Irfan Naseer.

 

Could you please help me with the integration of the Kaspersky with mcAfee ESM ?!

i know what i need to do in the McAfee, but no idea what to configure in the Kaspersky side.

Could you provide a screenshot of the Kaspersky Settings ?!

 

Thank you very much!!!

best regards

David

Highlighted
mikrotik
Level 11
Report Inappropriate Content
Message 9 of 12

Re: Kaspersky integration issue.

Hi David,

Firstly, Kaspersky Administration Console or KSC nothing has to do with SIEM for integration process.

Secondly, It is only Database of Kaspersky which is integrated with SIEM.

Lastly,  are you sure the account you are using for Pull method has DB access rights of KSC?  if yes then how are you sure?

Thank You!

 

 

Yours Sincerely,
Syed Irfan Naseer
Reliable Contributor David1111
Reliable Contributor
Report Inappropriate Content
Message 10 of 12

Re: Kaspersky integration issue.

Hi Syed Irfan Naseer
first of all, Thanks' on the Quick Response!

i still didn't get from the customer the User Account name and password.

Becuse the IT company that's handeling the Kaspersky dosn't whant to provide me that,
They Claim that they need to send it via Syslog, the problem is i dont get the syslog, besides that it means i will need to write a lot of Parsing REGEX rules..... 😞

It would be very kind of you, if you could provide for me a screenshot of the configurations on the Kaspersky side, then i will be able to get them configure it properlly.

Best Regards.

Thanks' again.

More McAfee Tools to Help You
  • Subscription Service Notification (SNS)
  • How-to: Endpoint Removal Tool
  • Support: Endpoint Security
  • eSupport: Policy Orchestrator
  • Community Help Hub

      New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.

    • Find Forum FAQs
    • Learn How to Earn Badges
    • Ask for Help
    Go to Community Help

    Join the Community

      Thousands of customers use the McAfee Community for peer-to-peer and expert product support. Enjoy these benefits with a free membership:

    • Get helpful solutions from McAfee experts.
    • Stay connected to product conversations that matter to you.
    • Participate in product groups led by McAfee employees.
    Join the Community
    Join the Community