Kaspersky
Question

Removable Storage Media and CDROM Read / Write Event Logs


Hello
I have following Kaspersky environment.
KSC Server 10.4.343
Kaspersky Endpoint for Windows Workstation 10.3

In workstation policy i have checked all the informational events to be stored for more than 30 days.
In workstation policy Device Control Notification settings i enable following informational events to be saved in "local log", "windows event log" and "notify on screen"
  1. Operation with the device allowed
  2. File operation performed
When CDROM read / write operations are performed i received the on screen notifications perfectly but on Kaspersky Security Center Events i cannot find these read write operations events on CDROM.

5 replies

Userlevel 3
Badge +2
Hello
I have following Kaspersky environment.
KSC Server 10.4.343
Kaspersky Endpoint for Windows Workstation 10.3

In workstation policy i have checked all the informational events to be stored for more than 30 days.
In workstation policy Device Control Notification settings i enable following informational events to be saved in "local log", "windows event log" and "notify on screen"
  1. Operation with the device allowed
  2. File operation performed
When CDROM read / write operations are performed i received the on screen notifications perfectly but on Kaspersky Security Center Events i cannot find these read write operations events on CDROM.

Hello!
Can this event be shown in properties of this host on KSC?
Thank you!

Hello
I have following Kaspersky environment.
KSC Server 10.4.343
Kaspersky Endpoint for Windows Workstation 10.3

In workstation policy i have checked all the informational events to be stored for more than 30 days.
In workstation policy Device Control Notification settings i enable following informational events to be saved in "local log", "windows event log" and "notify on screen"
  1. Operation with the device allowed
  2. File operation performed
When CDROM read / write operations are performed i received the on screen notifications perfectly but on Kaspersky Security Center Events i cannot find these read write operations events on CDROM.
Hello!
Can this event be shown in properties of this host on KSC?
Thank you!


No these events are not shown in properties of host.
I did not find these events in "Device Control Events Report" and "Informational Events Selection"
Userlevel 3
Badge +2
Hello!
So, as follows from provided information, you can only see on screen notifications, but there is no evens in KES or KSC?

Thank you!
Hello!
So, as follows from provided information, you can only see on screen notifications, but there is no evens in KES or KSC?

Thank you!

Thanks for your response
Yes notifications are working perfectly, I can see the device type: CDROM, Operation: Read / Write, Username and filename.
On KES reports i can see the read write events.
On KSC i got events as attached. Please view the attached image

I did not find any read write events regarding to CD/DVD on KSC

Reply / Ответить