- 필수 기능
- 시작하기
- Glossary
- 표준 속성
- Guides
- Agent
- 통합
- 개방형텔레메트리
- 개발자
- Administrator's Guide
- API
- Datadog Mobile App
- CoScreen
- Cloudcraft
- 앱 내
- 서비스 관리
- 인프라스트럭처
- 애플리케이션 성능
- APM
- Continuous Profiler
- 스팬 시각화
- 데이터 스트림 모니터링
- 데이터 작업 모니터링
- 디지털 경험
- 소프트웨어 제공
- 보안
- AI Observability
- 로그 관리
- 관리
Supported OS
Kaspersky - Overview
Kaspersky - Network and Web Security
Kaspersky - Threat Detection and Response
Kaspersky - System Audit
Kaspersky is a cybersecurity solution that detects, analyzes, and responds to advanced threats across multiple endpoints, blocking attacks, extracting threat patterns, and preventing future incidents.
This integration parses the following types of logs:
Visualize detailed insights into these logs through the out-of-the-box dashboards. Additionally, out-of-the-box detection rules are available to help you monitor and respond to potential security threats effectively.
The Kaspersky check is included in the Datadog Agent package. No additional installation is needed on your server.
Configure SIEM system integration for Syslog export using either the Administration Server or the Security Center Web Console. Refer to the links below for detailed instructions on each method
Prerequisite: Ensure that web plugins for Endpoint Security applications are installed.
This ensures that all relevant events from Kaspersky Endpoint Security applications are properly exported to the SIEM system via Syslog.
Run the Agent’s status subcommand and look for kaspersky
under the Checks section.
Kaspersky does not include any metrics.
Collecting logs is disabled by default in the Datadog Agent. Enable it in the datadog.yaml
file with:
logs_enabled: true
Add this configuration block to your kaspersky.d/conf.yaml
file to start collecting your Kaspersky logs. See the sample kaspersky.d/conf.yaml for available configuration options.
logs:
- type: tcp
port: <PORT>
source: kaspersky
service: kaspersky
Note:
PORT
: Port should be similar to the port provided in Syslog configuration over Kaspersky Security Center section.The Kaspersky integration does not include any events.
The Kaspersky integration does not include any service checks.
Permission denied while port binding:
If you see a Permission denied error while port binding in the Agent logs:
Binding to a port number under 1024 requires elevated permissions. Grant access to the port using the setcap
command:
sudo setcap CAP_NET_BIND_SERVICE=+ep /opt/datadog-agent/bin/agent/agent
Verify the setup is correct by running the getcap
command:
sudo getcap /opt/datadog-agent/bin/agent/agent
With the expected output:
/opt/datadog-agent/bin/agent/agent = cap_net_bind_service+ep
Note: Re-run this setcap
command every time you upgrade the Agent.
Data is not being collected:
Ensure traffic is bypassed from the configured port if the firewall is enabled.
Port already in use:
If you see the Port <PORT_NUMBER> Already in Use error, see the following instructions. The following example is for port 514:
Can't start UDP forwarder on port 514: listen udp :514: bind: address already in use
. This error occurs because by default, Syslog listens on port 514. To resolve this error, take one of the following steps:For further assistance, contact Datadog support.
Kaspersky - Overview
Kaspersky - Network and Web Security
Kaspersky - Threat Detection and Response
Kaspersky - System Audit