Aruba-Introspektion

IBM QRadar DSM for Aruba Introspect erfasst Ereignisse von einem Aruba Introspect-Gerät.

In der folgenden Tabelle werden die Spezifikationen für Aruba Introspect DSM beschrieben:
Tabelle 1. Aruba Introspect DSM-Spezifikationen
Spezifikation Wert
Hersteller Aruba
DSM-Name Aruba-Introspektion
Name der RPM-Datei DSM-ArubaIntrospect-QRadar_version-build_number.noarch.rpm
Unterstützte Versionen 1.6
Protokoll Syslog
Ereignisformat Name/Wert-Paar (NVP)
Aufgezeichnete Ereignistypen

Sicherheit

System

Interne Aktivität

Exfiltration

Infizierung

Befehl & Steuerung

Automatisch erkannt? Ja
Enthält Identität? Nein
Angepasste Eigenschaften einschließen? Nein
Weitere Informationen Website von Aruba (https://www.arubanetworks.com)
Führen Sie die folgenden Schritte aus, um Aruba Introspect in QRadarzu integrieren:
  1. Wenn automatische Updates nicht aktiviert sind, laden Sie die neuesten Versionen der RPMs von der IBM®-Support-Website herunter (http://www.ibm.com/support).
    • DSMCommon-RPM
    • ArubaIntrospect DSM-RPM
  2. Konfigurieren Sie Ihr Aruba Introspect-Gerät, um Syslog-Ereignisse an QRadarzu senden.
  3. Wenn QRadar die Protokollquelle nicht automatisch erkennt, fügen Sie eine Aruba Introspect-Protokollquelle auf dem QRadar Consolehinzu. In der folgenden Tabelle sind die Parameter beschrieben, die bestimmte Werte für die Aruba Introspect-Ereigniserfassung erfordern:
    Tabelle 2. Parameter für Aruba Introspect-Protokollquelle
    Parameter Wert
    Protokollquellentyp Aruba-Introspektion
    Protokollkonfiguration Syslog
    Protokollquellenkennung

    Eine eindeutige Kennung für die Protokollquelle.

  4. Um zu überprüfen, ob QRadar ordnungsgemäß konfiguriert ist, sehen Sie sich die folgende Tabelle an, um ein Beispiel für eine geparste Ereignisnachricht anzuzeigen.
    Die folgende Tabelle enthält eine Beispielereignisnachricht für Aruba Introspect.
    Tabelle 3. Aruba Introspect-Beispielereignisnachricht
    Ereignisname Untergeordnete Kategorie Beispielprotokollnachricht
    Cloud-Exfiltration Suspicious Activity
    May  6 20:04:38 <Server>May  7 03:04:38 lab-an-node msg_type=alert detection_time="2016-05-06 20:04:23 -07:00" alert_name="Large DropBox Upload" alert_type="Cloud Exfiltration" alert_category="Network Access" alert_severity=60 alert_confidence=20 attack_stage=Exfiltration user_name=<Username> src_host_name=example.com src_ip=<Source_IP_address> dest_ip=Destination_IP_address1>,<Destination_IP_address2>,... description="User <Username> on host example.com uploaded 324.678654 MB to Dropbox on May 05, 2016; compared with users in the whole Enterprise who uploaded an average of 22.851 KB  during the same day" alert_id=xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx_xxxxxxxxxxxxxxxx_Large_DropBox_Upload