Configuration d'Aruba ClearPass Policy Manager pour communiquer avec QRadar

Pour collecter des événements syslog à partir d'Aruba ClearPass Policy Manager, vous devez ajouter un serveur syslog externe pour l'hôte IBM QRadar , puis créer un ou plusieurs filtres syslog pour votre serveur syslog.

A propos de cette tâche

Pour les événements Session et Insight ®, l'analyse syntaxique complète des événements fonctionne uniquement pour les zones par défaut fournies par le gestionnaire de règles ClearPass d'Aruba. Les événements de session et d'Insight créés par un utilisateur et ayant différentes combinaisons de zones peuvent apparaître sous la forme Journal de session inconnuou Journal Insight inconnu.

Le tableau suivant présente les catégories de zone et leurs zones par défaut que vous pouvez utiliser :

Tableau 1. Catégories et zones par défaut pour les événements Session et Insight fournis par Aruba ClearPass Policy Manager
Modèle d'exportation Groupes de zones prédéfinis Colonnes sélectionnées par défaut
Journaux Insight Authentifications de rayon

Auth.Username (obligatoire)

Auth.Host-MAC-Address

Auth.Protocol = RADIUS (obligatoire)

Auth.NAS-IP-Address

CppmNode.CPPM-Node

Auth.Login-Status

Auth.Service

Auth.Roles

Auth.Enforcement-Profiles

Journaux Insight Authentifications de rayon ayant échoué

Auth.Username (obligatoire)

Auth.Host-MAC-Address

Auth.NAS-IP-Address

CppmNode.CPPM-Node

Auth.Service

CppmErrorCode.Error-Code-Details (obligatoire)

CppmAlert.Alertes

Journaux Insight Comptabilité RADIUS

Radius.Username (obligatoire)

Radius.Calling-Station-Id

Radius.Framed-IP-Address

Radius.NAS-IP-Address

Radius.Start-Time (obligatoire)

Radius.End-Time

Radius.Duration (obligatoire)

Radius.Input-bytes

Radius.Output-bytes

Journaux Insight tacacs Authentication

tacacs.Username (obligatoire)

tacacs.Remote-Address

tacacs.Request-Type

tacacs.NAS-IP-Address

tacacs.Service

tacacs.Auth-Source

tacacs.Roles

tacacs.Enforcement-Profiles

tacacs.Privilege-Level

Journaux Insight Authentification TACAS réussie

tacacs.Username (obligatoire)

TACACS.Error-code (obligatoire)

Comma.Login-Status

Tacacs.Roles

Journaux Insight tacacs Failed Authentication

tacacs.Username (obligatoire)

tacacs.Remote-Address

tacacs.Request-Type

tacacs.NAS-IP-Address

tacacs.Service

CppmErrorCode.Error-Code-Details

TACACS.Error-code (obligatoire)

CppmAlert.Alertes

Journaux Insight Authentification de l'application

Auth.Username (obligatoire)

Auth.Host-IP-Address (obligatoire)

Auth.Protocol (obligatoire)

CppmNode.CPPM-Node

Auth.Login-Status

Auth.Service

Auth.Source

Auth.Roles

Auth.Enforcement-Profiles

Journaux Insight Authentification d'application ayant échoué

Auth.Username (obligatoire)

Auth.Host-IP-Address (obligatoire)

Auth.Protocol (obligatoire)

CppmNode.CPPM-Node

Auth.Login-Status

Auth.Service

CppmErrorCode.Error-Code-Details (obligatoire)

CppmAlert.Alertes

Journaux Insight Points d'extrémité

Endpoint.MAC-Address (obligatoire)

Endpoint.MAC-Vendor

Endpoint.IP-Address

Endpoint.Username

Endpoint.Device-Category

Endpoint.Device-Family

Endpoint.Device-Name

Endpoint.Conflict

Endpoint.Status

Endpoint.Added-At

Endpoint.Updated-At

Journaux Insight Clearpass Guest

Guest.Username (obligatoire)

Guest.MAC-Address

Guest.Visitor-Name

Guest.Visitor-Company

Guest.Role-Name

Guest.Enabled

Guest.Created-At

Guest.Starts-At

Guest.Expires-At

Journaux Insight Inscription d'intégration

OnboardEnrollment.Username (obligatoire)

OnboardEnrollment.Device-Name

OnboardEnrollment.MAC-Address

OnboardEnrollment.Device-Product

OnboardEnrollment.Device-Version

OnboardEnrollment.Added-At

OnboardEnrollment.Updated-At

Journaux Insight Certificat d'intégration

OnboardCert.Username (obligatoire)

OnboardCert.Mac-Address

OnboardCert.Subject

OnboardCert.Issuer

OnboardCert.Valid-From

OnboardCert.Valid-To

OnboardCert.Revoked-At

Journaux Insight OCSP d'intégration

OnboardOCSP.Remote-Address (obligatoire)

OnboardOCSP.Response-Status-Name

OnboardOCSP.Timestamp

Journaux Insight Événements système Clearpass

CppmNode.CPPM-Node

CppmSystemEvent.Source (obligatoire)

CppmSystemEvent.Niveau

CppmSystemEvent.Category

CppmSystemEvent.Action

CppmSystemEvent.Timestamp

Journaux Insight Audit de configuration Clearpass

CppmConfigAudit.Name (obligatoire)

CppmConfigAudit.Action

CppmConfigAudit.Category

CppmConfigAudit.Updated-By

CppmConfigAudit.Updated-At

Journaux Insight Récapitulatif du genre de caractère

Endpoint.MAC-Address

Endpoint.IP-Address

Endpoint.Hostname

Endpoint.Usermame

Endpoint.System-Agent-Type

Endpoint.System-Agent-Version

Endpoint.System-Client-OS

Endpoint.System-Posture-Token (obligatoire)

Endpoint.Posture-Healthy

Endpoint.Posture-Unhealthy

Journaux Insight Récapitulatif du pare-feu du genre de caractère

Endpoint.MAC-Address (obligatoire)

Endpoint.IP-Address

Endpoint.Hostname

Endpoint.Usermame

Endpoint.System-Agent-Type

Endpoint.System-Agent-Version

Endpoint.System-Client-OS

Endpoint.System-Posture-Token

Endpoint.Firewall-APT (obligatoire)

Endpoint.Firewall-Input

Endpoint.Firewall-Output

Journaux Insight Récapitulatif de l'antivirus du genre de caractère

Endpoint.MAC-Address (obligatoire)

Endpoint.IP-Address

Endpoint.Hostname

Endpoint.Usermame

Endpoint.System-Agent-Type

Endpoint.System-Agent-Version

Endpoint.System-Client-OS

Endpoint.System-Posture-Token

Endpoint.Antivirus-APT (obligatoire)

Endpoint.Antivirus-Input

Endpoint. Antivirus-Output

Journaux Insight Récapitulatif des antispyware du genre de caractère

Endpoint.MAC-Address (obligatoire)

Endpoint.IP-Address

Endpoint.Hostname

Endpoint.Usermame

Endpoint.System-Agent-Type

Endpoint.System-Agent-Version

Endpoint.System-Client-OS

Endpoint.System-Posture-Token

Endpoint.Antispyware-APT (obligatoire)

Endpoint.Antispyware-Input

Endpoint.Antispyware-Output

Journaux Insight Récapitulatif du chiffrement de disque du genre de caractère

Endpoint.MAC-Address (obligatoire)

Endpoint.IP-Address

Endpoint.Hostname

Endpoint.Usermame

Endpoint.System-Agent-Type

Endpoint.System-Agent-Version

Endpoint.System-Client-OS

Endpoint.System-Posture-Token

Endpoint.DiskEncryption-APT (obligatoire)

Endpoint.DiskEncryption-Input

Endpoint.DiskEncryption-Output

Journaux Insight Récapitulatif des correctifs logiciels Windows

Endpoint.MAC-Address (obligatoire)

Endpoint.IP-Address

Endpoint.Hostname

Endpoint.Usermame

Endpoint.System-Agent-Type

Endpoint.System-Agent-Version

Endpoint.System-Client-OS

Endpoint.System-Posture-Token

Endpoint.HotFixes-APT (obligatoire)

Endpoint.HotFixes-Input

Endpoint.HotFixes-Output

Journaux de session Utilisateurs connectés

Common.Username (obligatoire)

Common.Service (obligatoire)

Common.Roles

Common.Host-MAC-Address (obligatoire)

RADIUS.Acct-Framed-IP-Address (obligatoire)

Common.NAS-IP-Address

Common.Request-Timestamp

Journaux de session Echecs d'authentification

Common.Username (obligatoire)

Common.Service (obligatoire)

Common.Roles

RADIUS.Auth-Source

RADIUS.Auth-Method

Common.System-Posture-Token

Common.Enforcement-Profiles

Common.Host-MAC-Address (obligatoire)

Common.NAS-IP-Address

Common.Error-Code (obligatoire)

Common.Alerts

Common.Request-Timestamp

Journaux de session Comptabilité RADIUS

RADIUS.Acct-Username (obligatoire)

RADIUS.Acct-NAS-IP-Address

RADIUS.Acct-NAS-Port

RADIUS.Acct-NAS-Port-Type

RADIUS.Acct-Calling-Station-Id

RADIUS.Acct-Framed-IP-Address

RADIUS.Acct-Session-Id (obligatoire)

RADIUS.Acct-Session-Time

RADIUS.Acct-Output-Pkts

RADIUS.Acct-Input-Pkts

RADIUS.Acct-Output-Octets

RADIUS.Acct-Input.Octets

RADIUS.Acct-Service-Name

RADIUS.Acct-Timestamp (obligatoire)

Journaux de session tacacs+ Administration

Common.Username

Common.Service

tacacs.Remote-Address (obligatoire)

tacacs.Privilege.Level (obligatoire)

Common.Request-Timestamp

Journaux de session tacacs+ Accounting

Common.Username

Common.Service

tacacs.Remote-Address (obligatoire)

tacacs.Acct-Flags (obligatoire)

tacacs.Privilege.Level (obligatoire)

Common.Request-Timestamp

Journaux de session Authentification Web

Common.Username

Common.Host-MAC-Address

WEBAUTH.Host-IP-Address (obligatoire)

Common.Roles

Common.System-Posture-Token

Common.Enforcement-Profiles

Common.Request-Timestamp

Journaux de session Accès invité

Common.Username (obligatoire)

RADIUS.Auth-Method

Common.Host-MAC-Address

Common.Roles

Common.System-Posture-Token

Common.Enforcement-Profiles

Common.Request-Timestamp

Journaux de session Accès invité réussi

Common.Username (obligatoire)

Common.Error-Code = 0 (obligatoire)

Common.Service

Common.Host-MAC-Address

Common.NAS-IP-Address

Common.Request-Timestamp

Common.System-Posture-Token

Common.Enforcement-Profiles

Common.Alerts

Journaux de session Accès réseau

Common.Username (obligatoire)

Common.Roles (obligatoire)

Common.Service

Common.Host-MAC-Address

Common.Request-Timestamp

Common.System-Posture-Token

Common.Enforcement-Profiles

Common.Alerts

Journaux de session Accès au réseau réussi

Common.Username (obligatoire)

Common.Roles (obligatoire)

Common.Error-Code = 0 (obligatoire)

Common.Service

Common.Host-MAC-Address

Common.NAS-IP-Address

Common.Request-Timestamp

Common.System-Posture-Token

Common.Enforcement-Profiles

Common.Alerts

Journaux de session Authentification MAC Common.Service (Doit contenir le mot-clé « mac-authentication »)

Common.Username

Common.Roles

Common.Host-MAC-Address

Common.NAS-IP-Address

Common.Request-Timestamp

Journaux de session Authentification SSID Common.Service (Doit contenir « SSID » OU « authentification »)

Common.Username

Common.Request-Timestamp

Common.Error-Code

Journaux de session Échec de l'authentification SSID

Common.Service (Doit contenir « SSID » OU « authentification »)

Common.Error-Code > 0 (obligatoire)

Common.Username

Common.Request-Timestamp

Common.Error-Code

Procédure

  1. Connectez-vous à votre serveur Aruba ClearPass Policy Manager.
  2. Démarrez la console d'administration.
  3. Cliquez sur Serveurs externes > Cibles Syslog.
  4. Cliquez sur Ajouter, puis configurez les détails de l'hôte QRadar .
  5. Dans la console d'administration, cliquez sur Serveurs externes > Filtres d'exportation Syslog.
  6. Cliquez sur Ajouter.
  7. Sélectionnez LEEF pour Exporter le type de format d'événement, puis sélectionnez le Serveur Syslog que vous avez ajouté.
  8. Cliquez sur Sauvegarder.