Aruba ClearPass Policy Manager für die Kommunikation mit QRadar konfigurieren
Zum Erfassen von Syslog-Ereignissen aus Aruba ClearPass Policy Manager müssen Sie einen externen Syslog-Server für den IBM QRadar -Host hinzufügen und anschließend mindestens einen Syslog-Filter für Ihren Syslog-Server erstellen.
Informationen zu dieser Task
In der folgenden Tabelle sind die Feldkategorien und ihre Standardfelder aufgeführt, die Sie verwenden können:
| Vorlage exportieren | Vordefinierte Feldgruppen | Standardmäßig ausgewählte Spalten |
|---|---|---|
| Insight-Protokolle | Radius-Authentifizierungen | Auth.Username (obligatorisch) Auth.Host-MAC-Address Auth.Protocol = RADIUS (obligatorisch) Auth.NAS-IP-Address CppmNodeCPPM-Knoten Auth.Login-Status Auth.Service Auth.Roles Auth.Enforcement-Profiles |
| Insight-Protokolle | Fehlgeschlagene Radius-Authentifizierungen | Auth.Username (obligatorisch) Auth.Host-MAC-Address Auth.NAS-IP-Address CppmNodeCPPM-Knoten Auth.Service CppmErrorCode.Error-Code-Details (obligatorisch) CppmAlert.Alerts |
| Insight-Protokolle | RADIUS-Abrechnung | Radius.Username (obligatorisch) Radius.Calling-Station-Id Radius.Framed-IP-Address Radius.NAS-IP-Address Radius.Start-Time (obligatorisch) Radius.End-Time Radius.Duration (obligatorisch) Radius.Input-bytes Radius.Output-bytes |
| Insight-Protokolle | TACACS-Authentifizierung | tacacs.Username (obligatorisch) tacacs.Remote-Address tacacs.Request-Type tacacs.NAS-IP-Address tacacs.Service tacacs.Auth-Source tacacs.Roles tacacs.Enforcement-Profiles tacacs.Privilege-Level |
| Insight-Protokolle | TACAS-Authentifizierung erfolgreich | tacacs.Username (obligatorisch) TACACS.Error-code (obligatorisch) Comma.Login-Status Tacacs.Roles |
| Insight-Protokolle | tacacs-Authentifizierung fehlgeschlagen | tacacs.Username (obligatorisch) tacacs.Remote-Address tacacs.Request-Type tacacs.NAS-IP-Address tacacs.Service CppmErrorCode.Fehler-Code-Details TACACS.Error-code (obligatorisch) CppmAlert.Alerts |
| Insight-Protokolle | Anwendungsauthentifizierung | Auth.Username (obligatorisch) Auth.Host-IP-Address (obligatorisch) Auth.Protocol (obligatorisch) CppmNodeCPPM-Knoten Auth.Login-Status Auth.Service Auth.Source Auth.Roles Auth.Enforcement-Profiles |
| Insight-Protokolle | Fehlgeschlagene Anwendungsauthentifizierung | Auth.Username (obligatorisch) Auth.Host-IP-Address (obligatorisch) Auth.Protocol (obligatorisch) CppmNodeCPPM-Knoten Auth.Login-Status Auth.Service CppmErrorCode.Error-Code-Details (obligatorisch) CppmAlert.Alerts |
| Insight-Protokolle | Endpunkte | Endpoint.MAC-Address (obligatorisch) Endpoint.MAC-Vendor Endpoint.IP-Address Endpoint.Username Endpoint.Device-Category Endpoint.Device-Family Endpoint.Device-Name Endpoint.Conflict Endpoint.Status Endpoint.Added-At Endpoint.Updated-At |
| Insight-Protokolle | Clearpass-Gast | Guest.Username (obligatorisch) Guest.MAC-Address Guest.Visitor-Name Guest.Visitor-Company Guest.Role-Name Guest.Enabled Guest.Created-At Guest.Starts-At Guest.Expires-At |
| Insight-Protokolle | Onboard-Registrierung | OnboardEnrollment.Username (obligatorisch) OnboardEnrollmentEinheitenname OnboardEnrollmentMAC-Adresse OnboardEnrollmentGerät-Produkt OnboardEnrollmentEinheit-Version OnboardEnrollmentHinzugefügt-Bei OnboardEnrollmentAktualisiert-Am |
| Insight-Protokolle | Onboard-Zertifikat | OnboardCert.Username (obligatorisch) OnboardCertMac-Adresse OnboardCert.Subject OnboardCertAussteller OnboardCertGültig von OnboardCertGültig bis OnboardCertWiderrufen-Um |
| Insight-Protokolle | Onboard-OCSP | OnboardOCSP.Remote-Address (obligatorisch) OnboardOCSP.Antwort-Status-Name OnboardOCSP.Zeitmarke |
| Insight-Protokolle | Clearpass-systemereignisse | CppmNodeCPPM-Knoten CppmSystemEvent.Source (obligatorisch) CppmSystemEvent.Level CppmSystemEvent.Kategorie CppmSystemEvent.Action CppmSystemEvent.Zeitstempel |
| Insight-Protokolle | Clearpass-Konfigurationsprüfung | CppmConfigAudit.Name (obligatorisch) CppmConfigAudit.Aktion CppmConfigAudit.Kategorie CppmConfigAudit.Updated-By CppmConfigAudit.Updated-At |
| Insight-Protokolle | Zusammenfassung der Einsatzleitung | Endpoint.MAC-Address Endpoint.IP-Address Endpoint.Hostname Endpoint.Usermame Endpoint.System-Agent-Type Endpoint.System-Agent-Version Endpoint.System-Client-OS Endpoint.System-Posture-Token (obligatorisch) Endpoint.Posture-Healthy Endpoint.Posture-Unhealthy |
| Insight-Protokolle | Posture-Firewall-Zusammenfassung | Endpoint.MAC-Address (obligatorisch) Endpoint.IP-Address Endpoint.Hostname Endpoint.Usermame Endpoint.System-Agent-Type Endpoint.System-Agent-Version Endpoint.System-Client-OS Endpoint.System-Posture-Token Endpoint.Firewall-APT (obligatorisch) Endpoint.Firewall-Input Endpoint.Firewall-Output |
| Insight-Protokolle | Zusammenfassung des Virenschutzes bei der Einsatzleitung | Endpoint.MAC-Address (obligatorisch) Endpoint.IP-Address Endpoint.Hostname Endpoint.Usermame Endpoint.System-Agent-Type Endpoint.System-Agent-Version Endpoint.System-Client-OS Endpoint.System-Posture-Token Endpoint.Antivirus-APT (obligatorisch) Endpoint.Antivirus-Input Endpunkt. Antivirus-Ausgabe |
| Insight-Protokolle | Posture Antispyware-Zusammenfassung | Endpoint.MAC-Address (obligatorisch) Endpoint.IP-Address Endpoint.Hostname Endpoint.Usermame Endpoint.System-Agent-Type Endpoint.System-Agent-Version Endpoint.System-Client-OS Endpoint.System-Posture-Token Endpoint.Antispyware-APT (obligatorisch) Endpoint.Antispyware-Input Endpoint.Antispyware-Output |
| Insight-Protokolle | Zusammenfassung der DiskEncryption -Einsatzleitung | Endpoint.MAC-Address (obligatorisch) Endpoint.IP-Address Endpoint.Hostname Endpoint.Usermame Endpoint.System-Agent-Type Endpoint.System-Agent-Version Endpoint.System-Client-OS Endpoint.System-Posture-Token Endpoint.DiskEncryption-APT (obligatorisch) Endpoint.DiskEncryption-Input Endpoint.DiskEncryption-Output |
| Insight-Protokolle | Zusammenfassung der Windows-Hotfixes für Einsatzleitung | Endpoint.MAC-Address (obligatorisch) Endpoint.IP-Address Endpoint.Hostname Endpoint.Usermame Endpoint.System-Agent-Type Endpoint.System-Agent-Version Endpoint.System-Client-OS Endpoint.System-Posture-Token Endpoint.HotFixes-APT (obligatorisch) Endpoint.HotFixes-Input Endpoint.HotFixes-Output |
| Sitzungsprotokolle | Angemeldete Benutzer | Common.Username (obligatorisch) Common.Service (obligatorisch) Common.Roles Common.Host-MAC-Address (obligatorisch) RADIUS.Acct-Framed-IP-Address (obligatorisch) Common.NAS-IP-Address Common.Request-Timestamp |
| Sitzungsprotokolle | Fehlgeschlagene Authentifizierungen | Common.Username (obligatorisch) Common.Service (obligatorisch) Common.Roles RADIUS.Auth-Source RADIUS.Auth-Method Common.System-Posture-Token Common.Enforcement-Profiles Common.Host-MAC-Address (obligatorisch) Common.NAS-IP-Address Common.Error-Code (obligatorisch) Common.Alerts Common.Request-Timestamp |
| Sitzungsprotokolle | RADIUS-Abrechnung | RADIUS.Acct-Username (obligatorisch) RADIUS.Acct-NAS-IP-Address RADIUS.Acct-NAS-Port RADIUS.Acct-NAS-Port-Type RADIUS.Acct-Calling-Station-Id RADIUS.Acct-Framed-IP-Address RADIUS.Acct-Session-Id (obligatorisch) RADIUS.Acct-Session-Time RADIUS.Acct-Output-Pkts RADIUS.Acct-Input-Pkts RADIUS.Acct-Output-Octets RADIUS.Acct-Input.Octets RADIUS.Acct-Service-Name RADIUS.Acct-Timestamp (obligatorisch) |
| Sitzungsprotokolle | tacacs + Verwaltung | Common.Username Common.Service tacacs.Remote-Address (obligatorisch) tacacs.Privilege.Level (obligatorisch) Common.Request-Timestamp |
| Sitzungsprotokolle | tacacs + Abrechnung | Common.Username Common.Service tacacs.Remote-Address (obligatorisch) tacacs.Acct-Flags (obligatorisch) tacacs.Privilege.Level (obligatorisch) Common.Request-Timestamp |
| Sitzungsprotokolle | Webauthentifizierung | Common.Username Common.Host-MAC-Address WEBAUTH.Host-IP-Address (obligatorisch) Common.Roles Common.System-Posture-Token Common.Enforcement-Profiles Common.Request-Timestamp |
| Sitzungsprotokolle | Gastzugriff | Common.Username (obligatorisch) RADIUS.Auth-Method Common.Host-MAC-Address Common.Roles Common.System-Posture-Token Common.Enforcement-Profiles Common.Request-Timestamp |
| Sitzungsprotokolle | Gastzugang erfolgreich | Common.Username (obligatorisch) Common.Error-Code = 0 (obligatorisch) Common.Service Common.Host-MAC-Address Common.NAS-IP-Address Common.Request-Timestamp Common.System-Posture-Token Common.Enforcement-Profiles Common.Alerts |
| Sitzungsprotokolle | Netzwerkzugriff | Common.Username (obligatorisch) Common.Roles (obligatorisch) Common.Service Common.Host-MAC-Address Common.Request-Timestamp Common.System-Posture-Token Common.Enforcement-Profiles Common.Alerts |
| Sitzungsprotokolle | Netzwerkzugriff erfolgreich | Common.Username (obligatorisch) Common.Roles (obligatorisch) Common.Error-Code = 0 (obligatorisch) Common.Service Common.Host-MAC-Address Common.NAS-IP-Address Common.Request-Timestamp Common.System-Posture-Token Common.Enforcement-Profiles Common.Alerts |
| Sitzungsprotokolle | MAC-Authentifizierung | Common.Service (Muss das Schlüsselwort „mac-authentication” enthalten) Common.Username Common.Roles Common.Host-MAC-Address Common.NAS-IP-Address Common.Request-Timestamp |
| Sitzungsprotokolle | SSID-Authentifizierung | Common.Service (Muss „SSID“ ODER „Authentifizierung“ enthalten) Common.Username Common.Request-Timestamp Common.Error-Code |
| Sitzungsprotokolle | SSID-Authentifizierung fehlgeschlagen | Common.Service (Muss „SSID“ ODER „Authentifizierung“ enthalten) Common.Error-Code > 0 (obligatorisch) Common.Username Common.Request-Timestamp Common.Error-Code |
Vorgehensweise
- Melden Sie sich bei Ihrem ClearPass Policy Manager-Server an.
- Starten Sie die Administrationskonsole.
- Klicken Sie auf “.
- Klicken Sie auf Hinzufügenund konfigurieren Sie dann die Details für den QRadar -Host.
- Klicken Sie in der Verwaltungskonsole auf “.
- Klicken Sie auf Hinzufügen.
- Wählen Sie LEEF für die Ereignistyp exportierenund dann die Syslog-Server aus, die Sie hinzugefügt haben.
- Klicken Sie auf Speichern.