본문으로 건너뛰기

ESET PROTECT Integration

Overview

ESET PROTECT provides centralized management for ESET endpoint security products with threat detection, device control, and full disk encryption. KYRA MDR collects ESET events via syslog or the ESET PROTECT API for comprehensive endpoint monitoring.

Prerequisites

  • A KYRA MDR Collector installed and running
  • ESET PROTECT Server with administrative access
  • ESET PROTECT version 10.x or later
  • Network connectivity from the server to the collector on port 514

Configuration

Configure syslog export in ESET PROTECT:

  1. Log in to the ESET PROTECT Web Console
  2. Navigate to More > Server Configuration > Advanced Settings
  3. Under Syslog Server, configure:
Enable Syslog: Yes
Syslog Server Host: <collector-ip>
Syslog Server Port: 514
Format: JSON
Transport: TCP
Export Logs: Detections, Firewall, HIPS, Audit
  1. Click Save
  2. Verify events under More > Server Configuration > Syslog status

Collected Log Types

Log TypeDescriptionSecurity Use
DetectionsMalware and threat detectionsEndpoint protection monitoring
FirewallESET Firewall eventsHost network security
HIPSHost intrusion prevention eventsBehavioral threat detection
Device ControlUSB and peripheral eventsData security, policy enforcement
Web ControlWeb access filteringContent filtering
AuditAdministrative and user actionsCompliance auditing

Troubleshooting

Syslog not exporting: Verify syslog is enabled in server configuration. Restart the ESET PROTECT Server service after enabling.

JSON parsing errors: KYRA MDR expects ESET JSON format. Verify the syslog format is set to JSON.

Missing agent events: Events from endpoints must first report to the ESET PROTECT Server before being forwarded via syslog.

Contact kyra@seekerslab.com for support.