Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.
Table of Contents
maxLevel2
minLevel2
typeflat

...

The tables cef0.kaspersky.* identify events in CEF format generated by Kaspersky services.

Tag structure

Events in CEF format don't have a specific tag structure, as explained in Technologies supported in CEF syslog format. They are always sent to a table with the structure cef0.deviceVendor.deviceProduct.

In this case, the valid data tables are:

Tag

Data table

cef0.kaspersky.kaspersky

cef0.kaspersky.kaspersky

cef0.kasperskylab.securitycenter

cef0.kasperskylab.securitycenter

cef0.kaspersky.securityCenter

cef0.kaspersky.securityCenter

cef0.kaspersky.securityCenterNetworkAgent

cef0.kaspersky.securityCenterNetworkAgent

cef0.kaspersky.kasperskyAntivirusForWindowsServersEnterpriseEdition

cef0.kaspersky.kasperskyAntivirusForWindowsServersEnterpriseEdition

cef0.kaspersky.kasperskyEndpointSecurityForWindows

cef0.kaspersky.kasperskyEndpointSecurityForWindows

How is the data sent to Devo?

Logs must be sent to the Devo platform via the Devo Relay to secure communication.