Aruba ClearPass Policy Manager für die Kommunikation mit QRadar konfigurieren

Zum Erfassen von Syslog-Ereignissen aus Aruba ClearPass Policy Manager müssen Sie einen externen Syslog-Server für den IBM QRadar -Host hinzufügen und anschließend mindestens einen Syslog-Filter für Ihren Syslog-Server erstellen.

Informationen zu dieser Task

Für Session-und Insight ® -Ereignisse funktioniert das vollständige Ereignisparsing nur für die Standardfelder, die von Aruba ClearPass Policy Manager bereitgestellt werden. Sitzung-und Insight-Ereignisse, die von einem Benutzer erstellt werden und unterschiedliche Kombinationen von Feldern aufweisen, können als Unbekanntes Sitzungsprotokolloder Unbekanntes Insight-Protokollangezeigt werden.

In der folgenden Tabelle sind die Feldkategorien und ihre Standardfelder aufgeführt, die Sie verwenden können:

Tabelle 1. Von Aruba ClearPass Policy Manager bereitgestellte Standardkategorien und -felder für Session-und Insight-Ereignisse
Vorlage exportieren Vordefinierte Feldgruppen Standardmäßig ausgewählte Spalten
Insight-Protokolle Radius-Authentifizierungen

Auth.Username (obligatorisch)

Auth.Host-MAC-Address

Auth.Protocol = RADIUS (obligatorisch)

Auth.NAS-IP-Address

CppmNodeCPPM-Knoten

Auth.Login-Status

Auth.Service

Auth.Roles

Auth.Enforcement-Profiles

Insight-Protokolle Fehlgeschlagene Radius-Authentifizierungen

Auth.Username (obligatorisch)

Auth.Host-MAC-Address

Auth.NAS-IP-Address

CppmNodeCPPM-Knoten

Auth.Service

CppmErrorCode.Error-Code-Details (obligatorisch)

CppmAlert.Alerts

Insight-Protokolle RADIUS-Abrechnung

Radius.Username (obligatorisch)

Radius.Calling-Station-Id

Radius.Framed-IP-Address

Radius.NAS-IP-Address

Radius.Start-Time (obligatorisch)

Radius.End-Time

Radius.Duration (obligatorisch)

Radius.Input-bytes

Radius.Output-bytes

Insight-Protokolle TACACS-Authentifizierung

tacacs.Username (obligatorisch)

tacacs.Remote-Address

tacacs.Request-Type

tacacs.NAS-IP-Address

tacacs.Service

tacacs.Auth-Source

tacacs.Roles

tacacs.Enforcement-Profiles

tacacs.Privilege-Level

Insight-Protokolle TACAS-Authentifizierung erfolgreich

tacacs.Username (obligatorisch)

TACACS.Error-code (obligatorisch)

Comma.Login-Status

Tacacs.Roles

Insight-Protokolle tacacs-Authentifizierung fehlgeschlagen

tacacs.Username (obligatorisch)

tacacs.Remote-Address

tacacs.Request-Type

tacacs.NAS-IP-Address

tacacs.Service

CppmErrorCode.Fehler-Code-Details

TACACS.Error-code (obligatorisch)

CppmAlert.Alerts

Insight-Protokolle Anwendungsauthentifizierung

Auth.Username (obligatorisch)

Auth.Host-IP-Address (obligatorisch)

Auth.Protocol (obligatorisch)

CppmNodeCPPM-Knoten

Auth.Login-Status

Auth.Service

Auth.Source

Auth.Roles

Auth.Enforcement-Profiles

Insight-Protokolle Fehlgeschlagene Anwendungsauthentifizierung

Auth.Username (obligatorisch)

Auth.Host-IP-Address (obligatorisch)

Auth.Protocol (obligatorisch)

CppmNodeCPPM-Knoten

Auth.Login-Status

Auth.Service

CppmErrorCode.Error-Code-Details (obligatorisch)

CppmAlert.Alerts

Insight-Protokolle Endpunkte

Endpoint.MAC-Address (obligatorisch)

Endpoint.MAC-Vendor

Endpoint.IP-Address

Endpoint.Username

Endpoint.Device-Category

Endpoint.Device-Family

Endpoint.Device-Name

Endpoint.Conflict

Endpoint.Status

Endpoint.Added-At

Endpoint.Updated-At

Insight-Protokolle Clearpass-Gast

Guest.Username (obligatorisch)

Guest.MAC-Address

Guest.Visitor-Name

Guest.Visitor-Company

Guest.Role-Name

Guest.Enabled

Guest.Created-At

Guest.Starts-At

Guest.Expires-At

Insight-Protokolle Onboard-Registrierung

OnboardEnrollment.Username (obligatorisch)

OnboardEnrollmentEinheitenname

OnboardEnrollmentMAC-Adresse

OnboardEnrollmentGerät-Produkt

OnboardEnrollmentEinheit-Version

OnboardEnrollmentHinzugefügt-Bei

OnboardEnrollmentAktualisiert-Am

Insight-Protokolle Onboard-Zertifikat

OnboardCert.Username (obligatorisch)

OnboardCertMac-Adresse

OnboardCert.Subject

OnboardCertAussteller

OnboardCertGültig von

OnboardCertGültig bis

OnboardCertWiderrufen-Um

Insight-Protokolle Onboard-OCSP

OnboardOCSP.Remote-Address (obligatorisch)

OnboardOCSP.Antwort-Status-Name

OnboardOCSP.Zeitmarke

Insight-Protokolle Clearpass-systemereignisse

CppmNodeCPPM-Knoten

CppmSystemEvent.Source (obligatorisch)

CppmSystemEvent.Level

CppmSystemEvent.Kategorie

CppmSystemEvent.Action

CppmSystemEvent.Zeitstempel

Insight-Protokolle Clearpass-Konfigurationsprüfung

CppmConfigAudit.Name (obligatorisch)

CppmConfigAudit.Aktion

CppmConfigAudit.Kategorie

CppmConfigAudit.Updated-By

CppmConfigAudit.Updated-At

Insight-Protokolle Zusammenfassung der Einsatzleitung

Endpoint.MAC-Address

Endpoint.IP-Address

Endpoint.Hostname

Endpoint.Usermame

Endpoint.System-Agent-Type

Endpoint.System-Agent-Version

Endpoint.System-Client-OS

Endpoint.System-Posture-Token (obligatorisch)

Endpoint.Posture-Healthy

Endpoint.Posture-Unhealthy

Insight-Protokolle Posture-Firewall-Zusammenfassung

Endpoint.MAC-Address (obligatorisch)

Endpoint.IP-Address

Endpoint.Hostname

Endpoint.Usermame

Endpoint.System-Agent-Type

Endpoint.System-Agent-Version

Endpoint.System-Client-OS

Endpoint.System-Posture-Token

Endpoint.Firewall-APT (obligatorisch)

Endpoint.Firewall-Input

Endpoint.Firewall-Output

Insight-Protokolle Zusammenfassung des Virenschutzes bei der Einsatzleitung

Endpoint.MAC-Address (obligatorisch)

Endpoint.IP-Address

Endpoint.Hostname

Endpoint.Usermame

Endpoint.System-Agent-Type

Endpoint.System-Agent-Version

Endpoint.System-Client-OS

Endpoint.System-Posture-Token

Endpoint.Antivirus-APT (obligatorisch)

Endpoint.Antivirus-Input

Endpunkt. Antivirus-Ausgabe

Insight-Protokolle Posture Antispyware-Zusammenfassung

Endpoint.MAC-Address (obligatorisch)

Endpoint.IP-Address

Endpoint.Hostname

Endpoint.Usermame

Endpoint.System-Agent-Type

Endpoint.System-Agent-Version

Endpoint.System-Client-OS

Endpoint.System-Posture-Token

Endpoint.Antispyware-APT (obligatorisch)

Endpoint.Antispyware-Input

Endpoint.Antispyware-Output

Insight-Protokolle Zusammenfassung der DiskEncryption -Einsatzleitung

Endpoint.MAC-Address (obligatorisch)

Endpoint.IP-Address

Endpoint.Hostname

Endpoint.Usermame

Endpoint.System-Agent-Type

Endpoint.System-Agent-Version

Endpoint.System-Client-OS

Endpoint.System-Posture-Token

Endpoint.DiskEncryption-APT (obligatorisch)

Endpoint.DiskEncryption-Input

Endpoint.DiskEncryption-Output

Insight-Protokolle Zusammenfassung der Windows-Hotfixes für Einsatzleitung

Endpoint.MAC-Address (obligatorisch)

Endpoint.IP-Address

Endpoint.Hostname

Endpoint.Usermame

Endpoint.System-Agent-Type

Endpoint.System-Agent-Version

Endpoint.System-Client-OS

Endpoint.System-Posture-Token

Endpoint.HotFixes-APT (obligatorisch)

Endpoint.HotFixes-Input

Endpoint.HotFixes-Output

Sitzungsprotokolle Angemeldete Benutzer

Common.Username (obligatorisch)

Common.Service (obligatorisch)

Common.Roles

Common.Host-MAC-Address (obligatorisch)

RADIUS.Acct-Framed-IP-Address (obligatorisch)

Common.NAS-IP-Address

Common.Request-Timestamp

Sitzungsprotokolle Fehlgeschlagene Authentifizierungen

Common.Username (obligatorisch)

Common.Service (obligatorisch)

Common.Roles

RADIUS.Auth-Source

RADIUS.Auth-Method

Common.System-Posture-Token

Common.Enforcement-Profiles

Common.Host-MAC-Address (obligatorisch)

Common.NAS-IP-Address

Common.Error-Code (obligatorisch)

Common.Alerts

Common.Request-Timestamp

Sitzungsprotokolle RADIUS-Abrechnung

RADIUS.Acct-Username (obligatorisch)

RADIUS.Acct-NAS-IP-Address

RADIUS.Acct-NAS-Port

RADIUS.Acct-NAS-Port-Type

RADIUS.Acct-Calling-Station-Id

RADIUS.Acct-Framed-IP-Address

RADIUS.Acct-Session-Id (obligatorisch)

RADIUS.Acct-Session-Time

RADIUS.Acct-Output-Pkts

RADIUS.Acct-Input-Pkts

RADIUS.Acct-Output-Octets

RADIUS.Acct-Input.Octets

RADIUS.Acct-Service-Name

RADIUS.Acct-Timestamp (obligatorisch)

Sitzungsprotokolle tacacs + Verwaltung

Common.Username

Common.Service

tacacs.Remote-Address (obligatorisch)

tacacs.Privilege.Level (obligatorisch)

Common.Request-Timestamp

Sitzungsprotokolle tacacs + Abrechnung

Common.Username

Common.Service

tacacs.Remote-Address (obligatorisch)

tacacs.Acct-Flags (obligatorisch)

tacacs.Privilege.Level (obligatorisch)

Common.Request-Timestamp

Sitzungsprotokolle Webauthentifizierung

Common.Username

Common.Host-MAC-Address

WEBAUTH.Host-IP-Address (obligatorisch)

Common.Roles

Common.System-Posture-Token

Common.Enforcement-Profiles

Common.Request-Timestamp

Sitzungsprotokolle Gastzugriff

Common.Username (obligatorisch)

RADIUS.Auth-Method

Common.Host-MAC-Address

Common.Roles

Common.System-Posture-Token

Common.Enforcement-Profiles

Common.Request-Timestamp

Sitzungsprotokolle Gastzugang erfolgreich

Common.Username (obligatorisch)

Common.Error-Code = 0 (obligatorisch)

Common.Service

Common.Host-MAC-Address

Common.NAS-IP-Address

Common.Request-Timestamp

Common.System-Posture-Token

Common.Enforcement-Profiles

Common.Alerts

Sitzungsprotokolle Netzwerkzugriff

Common.Username (obligatorisch)

Common.Roles (obligatorisch)

Common.Service

Common.Host-MAC-Address

Common.Request-Timestamp

Common.System-Posture-Token

Common.Enforcement-Profiles

Common.Alerts

Sitzungsprotokolle Netzwerkzugriff erfolgreich

Common.Username (obligatorisch)

Common.Roles (obligatorisch)

Common.Error-Code = 0 (obligatorisch)

Common.Service

Common.Host-MAC-Address

Common.NAS-IP-Address

Common.Request-Timestamp

Common.System-Posture-Token

Common.Enforcement-Profiles

Common.Alerts

Sitzungsprotokolle MAC-Authentifizierung Common.Service (Muss das Schlüsselwort „mac-authentication” enthalten)

Common.Username

Common.Roles

Common.Host-MAC-Address

Common.NAS-IP-Address

Common.Request-Timestamp

Sitzungsprotokolle SSID-Authentifizierung Common.Service (Muss „SSID“ ODER „Authentifizierung“ enthalten)

Common.Username

Common.Request-Timestamp

Common.Error-Code

Sitzungsprotokolle SSID-Authentifizierung fehlgeschlagen

Common.Service (Muss „SSID“ ODER „Authentifizierung“ enthalten)

Common.Error-Code > 0 (obligatorisch)

Common.Username

Common.Request-Timestamp

Common.Error-Code

Vorgehensweise

  1. Melden Sie sich bei Ihrem ClearPass Policy Manager-Server an.
  2. Starten Sie die Administrationskonsole.
  3. Klicken Sie auf „Externe Server “ > „Syslog-Ziele “.
  4. Klicken Sie auf Hinzufügenund konfigurieren Sie dann die Details für den QRadar -Host.
  5. Klicken Sie in der Verwaltungskonsole auf „Externe Server “ > „Syslog-Exportfilter “.
  6. Klicken Sie auf Hinzufügen.
  7. Wählen Sie LEEF für die Ereignistyp exportierenund dann die Syslog-Server aus, die Sie hinzugefügt haben.
  8. Klicken Sie auf Speichern.