Configuración de Aruba ClearPass Policy Manager para comunicarse con QRadar
Para recopilar sucesos de syslog de Aruba ClearPass Policy Manager, debe añadir un servidor syslog externo para el host IBM QRadar y, a continuación, crear uno o varios filtros de syslog para el servidor syslog.
Acerca de esta tarea
La tabla siguiente muestra las categorías de campo y sus campos predeterminados que puede utilizar:
| Plantilla de exportación | Grupos de campos predefinidos | Columnas seleccionadas por omisión |
|---|---|---|
| Registros de Insight | Autenticaciones Radius | Auth.Username (obligatorio) Auth.Host-MAC-Address Auth.Protocol = RADIUS (obligatorio) Auth.NAS-IP-Address CppmNode.CPPM-Nodo Auth.Login-Status Auth.Service Auth.Roles Auth.Enforcement-Profiles |
| Registros de Insight | Autenticaciones anómalas de radio | Auth.Username (obligatorio) Auth.Host-MAC-Address Auth.NAS-IP-Address CppmNode.CPPM-Nodo Auth.Service CppmErrorCode.Error-Code-Details (obligatorio) CppmAlert.Alertas |
| Registros de Insight | Contabilidad RADIUS | Radius.Username (obligatorio) Radius.Calling-Station-Id Radius.Framed-IP-Address Radius.NAS-IP-Address Radius.Start-Time (obligatorio) Radius.End-Time Radius.Duration (obligatorio) Radius.Input-bytes Radius.Output-bytes |
| Registros de Insight | Autenticación de TACACS | tacacs.Username (obligatorio) tacacs.Remote-Address tacacs.Request-Type tacacs.NAS-IP-Address tacacs.Service tacacs.Auth-Source tacacs.Roles tacacs.Enforcement-Profiles tacacs.Privilege-Level |
| Registros de Insight | La autenticación TACAS se ha realizado correctamente | tacacs.Username (obligatorio) TACACS.Error-code (obligatorio) Comma.Login-Status Tacacs.Roles |
| Registros de Insight | Autenticación fallida de tacacos | tacacs.Username (obligatorio) tacacs.Remote-Address tacacs.Request-Type tacacs.NAS-IP-Address tacacs.Service CppmErrorCode.Error-Code-Details TACACS.Error-code (obligatorio) CppmAlert.Alertas |
| Registros de Insight | Autenticación de la aplicación | Auth.Username (obligatorio) Auth.Host-IP-Address (obligatorio) Auth.Protocol (obligatorio) CppmNode.CPPM-Nodo Auth.Login-Status Auth.Service Auth.Source Auth.Roles Auth.Enforcement-Profiles |
| Registros de Insight | Autenticación de aplicación anómala | Auth.Username (obligatorio) Auth.Host-IP-Address (obligatorio) Auth.Protocol (obligatorio) CppmNode.CPPM-Nodo Auth.Login-Status Auth.Service CppmErrorCode.Error-Code-Details (obligatorio) CppmAlert.Alertas |
| Registros de Insight | Puntos finales | Endpoint.MAC-Address (obligatorio) Endpoint.MAC-Vendor Endpoint.IP-Address Endpoint.Username Endpoint.Device-Category Endpoint.Device-Family Endpoint.Device-Name Endpoint.Conflict Endpoint.Status Endpoint.Added-At Endpoint.Updated-At |
| Registros de Insight | Clearpass Invitado | Guest.Username (obligatorio) Guest.MAC-Address Guest.Visitor-Name Guest.Visitor-Company Guest.Role-Name Guest.Enabled Guest.Created-At Guest.Starts-At Guest.Expires-At |
| Registros de Insight | Inscripción a bordo | OnboardEnrollment.Username (obligatorio) OnboardEnrollment.Nombre de dispositivo OnboardEnrollment.MAC-Dirección OnboardEnrollment.Dispositivo-Producto OnboardEnrollment.Dispositivo-Versión OnboardEnrollment.Añadido-En OnboardEnrollment.Actualizado-En |
| Registros de Insight | Certificado A bordo | OnboardCert.Username (obligatorio) OnboardCert.Mac-Dirección OnboardCert.Asunto OnboardCert.Emisor OnboardCert.Válido-Desde OnboardCert.Válido-Para OnboardCert.Revocado-En |
| Registros de Insight | OCSP a bordo | OnboardOCSP.Remote-Address (obligatorio) OnboardOCSP.Respuesta-Estado-Nombre OnboardOCSP.Indicación de fecha y hora |
| Registros de Insight | Sucesos del sistema de Clearpass | CppmNode.CPPM-Nodo CppmSystemEvent.Source (obligatorio) CppmSystemEvent.Level CppmSystemEvent.Categoría CppmSystemEvent.Acción CppmSystemEvent.Timestamp |
| Registros de Insight | Auditoría de configuración de Clearpass | CppmConfigAudit.Name (obligatorio) CppmConfigAudit.Acción CppmConfigAudit.Categoría CppmConfigAudit.Updated-By CppmConfigAudit.Updated-At |
| Registros de Insight | Resumen de postura | Endpoint.MAC-Address Endpoint.IP-Address Endpoint.Hostname Endpoint.Usermame Endpoint.System-Agent-Type Endpoint.System-Agent-Version Endpoint.System-Client-OS Endpoint.System-Posture-Token (obligatorio) Endpoint.Posture-Healthy Endpoint.Posture-Unhealthy |
| Registros de Insight | Resumen del cortafuegos de postura | Endpoint.MAC-Address (obligatorio) Endpoint.IP-Address Endpoint.Hostname Endpoint.Usermame Endpoint.System-Agent-Type Endpoint.System-Agent-Version Endpoint.System-Client-OS Endpoint.System-Posture-Token Endpoint.Firewall-APT (obligatorio) Endpoint.Firewall-Input Endpoint.Firewall-Output |
| Registros de Insight | Resumen del antivirus de postura | Endpoint.MAC-Address (obligatorio) Endpoint.IP-Address Endpoint.Hostname Endpoint.Usermame Endpoint.System-Agent-Type Endpoint.System-Agent-Version Endpoint.System-Client-OS Endpoint.System-Posture-Token Endpoint.Antivirus-APT (obligatorio) Endpoint.Antivirus-Input Punto final. Antivirus-Salida |
| Registros de Insight | Resumen de Antispyware | Endpoint.MAC-Address (obligatorio) Endpoint.IP-Address Endpoint.Hostname Endpoint.Usermame Endpoint.System-Agent-Type Endpoint.System-Agent-Version Endpoint.System-Client-OS Endpoint.System-Posture-Token Endpoint.Antispyware-APT (obligatorio) Endpoint.Antispyware-Input Endpoint.Antispyware-Output |
| Registros de Insight | Resumen de DiskEncryption de postura | Endpoint.MAC-Address (obligatorio) Endpoint.IP-Address Endpoint.Hostname Endpoint.Usermame Endpoint.System-Agent-Type Endpoint.System-Agent-Version Endpoint.System-Client-OS Endpoint.System-Posture-Token Endpoint.DiskEncryption-APT (obligatorio) Endpoint.DiskEncryption-Input Endpoint.DiskEncryption-Output |
| Registros de Insight | Resumen de Hotfixes de Windows | Endpoint.MAC-Address (obligatorio) Endpoint.IP-Address Endpoint.Hostname Endpoint.Usermame Endpoint.System-Agent-Type Endpoint.System-Agent-Version Endpoint.System-Client-OS Endpoint.System-Posture-Token Endpoint.HotFixes-APT (obligatorio) Endpoint.HotFixes-Input Endpoint.HotFixes-Output |
| Registros de sesión | Anotado en usuarios | Common.Username (obligatorio) Common.Service (obligatorio) Common.Roles Common.Host-MAC-Address (obligatorio) RADIUS.Acct-Framed-IP-Address (obligatorio) Common.NAS-IP-Address Common.Request-Timestamp |
| Registros de sesión | Autenticaciones fallidas | Common.Username (obligatorio) Common.Service (obligatorio) Common.Roles RADIUS.Auth-Source RADIUS.Auth-Method Common.System-Posture-Token Common.Enforcement-Profiles Common.Host-MAC-Address (obligatorio) Common.NAS-IP-Address Common.Error-Code (obligatorio) Common.Alerts Common.Request-Timestamp |
| Registros de sesión | Contabilidad RADIUS | RADIUS.Acct-Username (obligatorio) RADIUS.Acct-NAS-IP-Address RADIUS.Acct-NAS-Port RADIUS.Acct-NAS-Port-Type RADIUS.Acct-Calling-Station-Id RADIUS.Acct-Framed-IP-Address RADIUS.Acct-Session-Id (obligatorio) RADIUS.Acct-Session-Time RADIUS.Acct-Output-Pkts RADIUS.Acct-Input-Pkts RADIUS.Acct-Output-Octets RADIUS.Acct-Input.Octets RADIUS.Acct-Service-Name RADIUS.Acct-Timestamp (obligatorio) |
| Registros de sesión | tacacs + Administration | Common.Username Common.Service tacacs.Remote-Address (obligatorio) tacacs.Privilege.Level (obligatorio) Common.Request-Timestamp |
| Registros de sesión | tacacs + Accounting | Common.Username Common.Service tacacs.Remote-Address (obligatorio) tacacs.Acct-Flags (obligatorio) tacacs.Privilege.Level (obligatorio) Common.Request-Timestamp |
| Registros de sesión | Autenticación web | Common.Username Common.Host-MAC-Address WEBAUTH.Host-IP-Address (obligatorio) Common.Roles Common.System-Posture-Token Common.Enforcement-Profiles Common.Request-Timestamp |
| Registros de sesión | Acceso de invitado | Common.Username (obligatorio) RADIUS.Auth-Method Common.Host-MAC-Address Common.Roles Common.System-Posture-Token Common.Enforcement-Profiles Common.Request-Timestamp |
| Registros de sesión | Acceso de invitado correcto | Common.Username (obligatorio) Common.Error-Code = 0 (obligatorio) Common.Service Common.Host-MAC-Address Common.NAS-IP-Address Common.Request-Timestamp Common.System-Posture-Token Common.Enforcement-Profiles Common.Alerts |
| Registros de sesión | Acceso a red | Common.Username (obligatorio) Common.Roles (obligatorio) Common.Service Common.Host-MAC-Address Common.Request-Timestamp Common.System-Posture-Token Common.Enforcement-Profiles Common.Alerts |
| Registros de sesión | Acceso a la red correcto | Common.Username (obligatorio) Common.Roles (obligatorio) Common.Error-Code = 0 (obligatorio) Common.Service Common.Host-MAC-Address Common.NAS-IP-Address Common.Request-Timestamp Common.System-Posture-Token Common.Enforcement-Profiles Common.Alerts |
| Registros de sesión | Autenticación MAC | Common.Service (Debe contener la palabra clave «mac-authentication») Common.Username Common.Roles Common.Host-MAC-Address Common.NAS-IP-Address Common.Request-Timestamp |
| Registros de sesión | Autenticación SSID | Common.Service (Debe contener «SSID» O «autenticación») Common.Username Common.Request-Timestamp Common.Error-Code |
| Registros de sesión | Error en la autenticación SSID | Common.Service (Debe contener «SSID» O «autenticación») Common.Error-Code > 0 (obligatorio) Common.Username Common.Request-Timestamp Common.Error-Code |
Procedimiento
- Inicie sesión en el servidor Aruba ClearPass Policy Manager.
- Inicie la Consola de administración.
- Haga clic en .
- Pulse Añadiry, a continuación, configure los detalles del host de QRadar .
- En la consola de administración, haga clic en
- Haga clic en Añadir.
- Seleccione LEEF para Exportar tipo de formato de sucesoy, a continuación, seleccione el Servidor de syslog que ha añadido.
- Haga clic en Guardar.