Priority: High (blocks SIEM onboarding of endpoint security events)
Dear Log360 Cloud Community
We are onboarding Kaspersky Security Center (KSC) event data into Log360 Cloud through syslog. The Log360 Cloud Agent receives the syslog connection, but the events never appear in Log360 Cloud. Please help us find out why the events are not being indexed and how to configure this correctly.
1. Environment
- Agent host: AV-Server, 172.16.5.242, Windows Server 2012 R2 Standard
- Log360 Cloud Agent service: log360cloudagent (Running, Automatic); syslog listener process SysEvtCol
- Agent version: [from Settings > Admin > Log360Cloud Agent]
- Syslog source: Kaspersky Security Center 15.1 Administration Server, installed on the same host (AV-Server, 172.16.5.242)
- In Log360 Cloud, AV-Server is already registered under Settings > Configuration > Devices > Windows Devices (Log Source Group: WindowsGroup, Status: Success).
2. KSC configuration (Administration Server > Events > Event export)
- Automatically export events to SIEM system database: Enabled
- SIEM system: Syslog (RFC 5424) format
- SIEM system server address: 172.16.5.242
- Port: 514
- Protocol: TCP/IP
- Maximum message size: 8000 bytes
- Critical, Functional failure and Warning events are marked "Export to SIEM system using Syslog" in the Administration Server and Kaspersky Endpoint Security policy event configuration.
3. What we verified
- SysEvtCol (the agent process) is listening on TCP 514:
Get-NetTCPConnection -LocalPort 514 -State Listen shows OwningProcess SysEvtCol. - KSC connects to the agent: a TCP connection from 172.16.5.242 to local port 514 shows as Established continuously over a 2-minute observation window.
- The agent can reach Log360 Cloud:
Test-NetConnection 136.143.189.36 -Port 443 shows TcpTestSucceeded True, and SysEvtCol holds an established connection to 136.143.189.36:443. - The log360cloudagent service was restarted, with no change.
- Windows event log collection from the same host works: the AV-Server device page shows Windows events received.
4. Issue observed
- No KSC syslog events can be found in Search (Today / Last 1 hour, no filters, keywords "Kaspersky" and "EICAR") after generating test detections.
- When we try to add 172.16.5.242 under Devices > Syslog Devices > + Add Device(s) with agent AV-Server, the device is not added. In Discover & Add, AV-Server appears already selected and greyed out.
- Separately, on the AV-Server device overview, Last Message Time stayed at 2026-10-02 12:00:05 and Collection Status showed "Scanning..." for an extended period.
5. Our questions
- Does Log360 Cloud support receiving syslog from a host that is already registered as a Windows device (agent-based), and in particular syslog sent to the agent on its own host?
- If yes, what configuration is required so these syslog messages are indexed and searchable? (For example, registering the host as a syslog device or an application, or a specific log type.)
- If no, what is the recommended architecture? For example, is a separate Log360 Cloud Agent on another server required to act as the syslog receiver?
- Is there a predefined parser for Kaspersky Security Center syslog (RFC 5424) in Log360 Cloud, or must we create a custom log format?
- Why might the AV-Server device stay at an old Last Message Time with Collection Status "Scanning..." even though the agent service is running and port 443 is reachable?
We can arrange a remote session at your convenience. Please let us know if you need any further information.
Kind regards,
Ahnaf Tahmeed