本文にスキップ

AhnLab V3 Endpoint Integration

Overview

This integration collects malware detection, behavioral analysis, quarantine events, and agent status logs from AhnLab V3 Endpoint Security and AhnLab EPP via the AhnLab Policy Center.

Supported products: AhnLab V3 Endpoint Security, AhnLab EPP, AhnLab EDR


Prerequisites

  • A KYRA MDR Collector installed and running (Installation Guide)
  • AhnLab Policy Center (EPP Center) with admin access
  • Network connectivity from the Policy Center to the collector on port 514

Note: Individual V3 clients cannot send syslog directly. The Policy Center aggregates logs from all endpoints and forwards them.


Configuration

Syslog Setup via Policy Center

  1. Log in to the AhnLab Policy Center (EPP Center)
  2. Navigate to 외부연동 > Syslog 서버 설정
  3. Add the KYRA Collector as a syslog destination:
SettingValue
Server IPYour KYRA Collector IP
Port514
ProtocolTCP (recommended)
  1. Select the event types to forward (malware, behavioral, quarantine, agent status)
  2. Apply the configuration

Sample Log Format

<14>date=20260320 time=103000 product=V3ES hostname=DESKTOP-ABC event=malware_detected name=Trojan/Win.Generic action=quarantine

Collected Log Types

Log TypeSecurity UsePriority
Malware detectionVirus/trojan/ransomware identificationCritical
Behavioral detectionSuspicious process behavior analysisHigh
Quarantine eventsIncident response trackingHigh
Real-time scanEndpoint protection statusMedium
Network protectionNetwork-level threat blockingMedium
Exploit preventionExploit attempt detectionHigh
Agent statusEndpoint health monitoringMedium
Engine/pattern updatesSignature freshness trackingLow

Troubleshooting

No Logs Received

  1. Verify the Policy Center syslog settings point to the correct collector IP
  2. Ensure port 514 is open between the Policy Center and the collector
  3. Confirm that V3 agents are reporting to the Policy Center

Missing Endpoint Events

  • Check that the target endpoints have active V3 agents connected to the Policy Center
  • Verify the selected event types include all desired categories

For additional help, contact kyra@seekerslab.com.