Configuration d'Aruba ClearPass Policy Manager pour communiquer avec QRadar
Pour collecter des événements syslog à partir d'Aruba ClearPass Policy Manager, vous devez ajouter un serveur syslog externe pour l'hôte IBM QRadar , puis créer un ou plusieurs filtres syslog pour votre serveur syslog.
A propos de cette tâche
Le tableau suivant présente les catégories de zone et leurs zones par défaut que vous pouvez utiliser :
| Modèle d'exportation | Groupes de zones prédéfinis | Colonnes sélectionnées par défaut |
|---|---|---|
| Journaux Insight | Authentifications de rayon | Auth.Username (obligatoire) Auth.Host-MAC-Address Auth.Protocol = RADIUS (obligatoire) Auth.NAS-IP-Address CppmNode.CPPM-Node Auth.Login-Status Auth.Service Auth.Roles Auth.Enforcement-Profiles |
| Journaux Insight | Authentifications de rayon ayant échoué | Auth.Username (obligatoire) Auth.Host-MAC-Address Auth.NAS-IP-Address CppmNode.CPPM-Node Auth.Service CppmErrorCode.Error-Code-Details (obligatoire) CppmAlert.Alertes |
| Journaux Insight | Comptabilité RADIUS | Radius.Username (obligatoire) Radius.Calling-Station-Id Radius.Framed-IP-Address Radius.NAS-IP-Address Radius.Start-Time (obligatoire) Radius.End-Time Radius.Duration (obligatoire) Radius.Input-bytes Radius.Output-bytes |
| Journaux Insight | tacacs Authentication | tacacs.Username (obligatoire) tacacs.Remote-Address tacacs.Request-Type tacacs.NAS-IP-Address tacacs.Service tacacs.Auth-Source tacacs.Roles tacacs.Enforcement-Profiles tacacs.Privilege-Level |
| Journaux Insight | Authentification TACAS réussie | tacacs.Username (obligatoire) TACACS.Error-code (obligatoire) Comma.Login-Status Tacacs.Roles |
| Journaux Insight | tacacs Failed Authentication | tacacs.Username (obligatoire) tacacs.Remote-Address tacacs.Request-Type tacacs.NAS-IP-Address tacacs.Service CppmErrorCode.Error-Code-Details TACACS.Error-code (obligatoire) CppmAlert.Alertes |
| Journaux Insight | Authentification de l'application | Auth.Username (obligatoire) Auth.Host-IP-Address (obligatoire) Auth.Protocol (obligatoire) CppmNode.CPPM-Node Auth.Login-Status Auth.Service Auth.Source Auth.Roles Auth.Enforcement-Profiles |
| Journaux Insight | Authentification d'application ayant échoué | Auth.Username (obligatoire) Auth.Host-IP-Address (obligatoire) Auth.Protocol (obligatoire) CppmNode.CPPM-Node Auth.Login-Status Auth.Service CppmErrorCode.Error-Code-Details (obligatoire) CppmAlert.Alertes |
| Journaux Insight | Points d'extrémité | Endpoint.MAC-Address (obligatoire) Endpoint.MAC-Vendor Endpoint.IP-Address Endpoint.Username Endpoint.Device-Category Endpoint.Device-Family Endpoint.Device-Name Endpoint.Conflict Endpoint.Status Endpoint.Added-At Endpoint.Updated-At |
| Journaux Insight | Clearpass Guest | Guest.Username (obligatoire) Guest.MAC-Address Guest.Visitor-Name Guest.Visitor-Company Guest.Role-Name Guest.Enabled Guest.Created-At Guest.Starts-At Guest.Expires-At |
| Journaux Insight | Inscription d'intégration | OnboardEnrollment.Username (obligatoire) OnboardEnrollment.Device-Name OnboardEnrollment.MAC-Address OnboardEnrollment.Device-Product OnboardEnrollment.Device-Version OnboardEnrollment.Added-At OnboardEnrollment.Updated-At |
| Journaux Insight | Certificat d'intégration | OnboardCert.Username (obligatoire) OnboardCert.Mac-Address OnboardCert.Subject OnboardCert.Issuer OnboardCert.Valid-From OnboardCert.Valid-To OnboardCert.Revoked-At |
| Journaux Insight | OCSP d'intégration | OnboardOCSP.Remote-Address (obligatoire) OnboardOCSP.Response-Status-Name OnboardOCSP.Timestamp |
| Journaux Insight | Événements système Clearpass | CppmNode.CPPM-Node CppmSystemEvent.Source (obligatoire) CppmSystemEvent.Niveau CppmSystemEvent.Category CppmSystemEvent.Action CppmSystemEvent.Timestamp |
| Journaux Insight | Audit de configuration Clearpass | CppmConfigAudit.Name (obligatoire) CppmConfigAudit.Action CppmConfigAudit.Category CppmConfigAudit.Updated-By CppmConfigAudit.Updated-At |
| Journaux Insight | Récapitulatif du genre de caractère | Endpoint.MAC-Address Endpoint.IP-Address Endpoint.Hostname Endpoint.Usermame Endpoint.System-Agent-Type Endpoint.System-Agent-Version Endpoint.System-Client-OS Endpoint.System-Posture-Token (obligatoire) Endpoint.Posture-Healthy Endpoint.Posture-Unhealthy |
| Journaux Insight | Récapitulatif du pare-feu du genre de caractère | Endpoint.MAC-Address (obligatoire) Endpoint.IP-Address Endpoint.Hostname Endpoint.Usermame Endpoint.System-Agent-Type Endpoint.System-Agent-Version Endpoint.System-Client-OS Endpoint.System-Posture-Token Endpoint.Firewall-APT (obligatoire) Endpoint.Firewall-Input Endpoint.Firewall-Output |
| Journaux Insight | Récapitulatif de l'antivirus du genre de caractère | Endpoint.MAC-Address (obligatoire) Endpoint.IP-Address Endpoint.Hostname Endpoint.Usermame Endpoint.System-Agent-Type Endpoint.System-Agent-Version Endpoint.System-Client-OS Endpoint.System-Posture-Token Endpoint.Antivirus-APT (obligatoire) Endpoint.Antivirus-Input Endpoint. Antivirus-Output |
| Journaux Insight | Récapitulatif des antispyware du genre de caractère | Endpoint.MAC-Address (obligatoire) Endpoint.IP-Address Endpoint.Hostname Endpoint.Usermame Endpoint.System-Agent-Type Endpoint.System-Agent-Version Endpoint.System-Client-OS Endpoint.System-Posture-Token Endpoint.Antispyware-APT (obligatoire) Endpoint.Antispyware-Input Endpoint.Antispyware-Output |
| Journaux Insight | Récapitulatif du chiffrement de disque du genre de caractère | Endpoint.MAC-Address (obligatoire) Endpoint.IP-Address Endpoint.Hostname Endpoint.Usermame Endpoint.System-Agent-Type Endpoint.System-Agent-Version Endpoint.System-Client-OS Endpoint.System-Posture-Token Endpoint.DiskEncryption-APT (obligatoire) Endpoint.DiskEncryption-Input Endpoint.DiskEncryption-Output |
| Journaux Insight | Récapitulatif des correctifs logiciels Windows | Endpoint.MAC-Address (obligatoire) Endpoint.IP-Address Endpoint.Hostname Endpoint.Usermame Endpoint.System-Agent-Type Endpoint.System-Agent-Version Endpoint.System-Client-OS Endpoint.System-Posture-Token Endpoint.HotFixes-APT (obligatoire) Endpoint.HotFixes-Input Endpoint.HotFixes-Output |
| Journaux de session | Utilisateurs connectés | Common.Username (obligatoire) Common.Service (obligatoire) Common.Roles Common.Host-MAC-Address (obligatoire) RADIUS.Acct-Framed-IP-Address (obligatoire) Common.NAS-IP-Address Common.Request-Timestamp |
| Journaux de session | Echecs d'authentification | Common.Username (obligatoire) Common.Service (obligatoire) Common.Roles RADIUS.Auth-Source RADIUS.Auth-Method Common.System-Posture-Token Common.Enforcement-Profiles Common.Host-MAC-Address (obligatoire) Common.NAS-IP-Address Common.Error-Code (obligatoire) Common.Alerts Common.Request-Timestamp |
| Journaux de session | Comptabilité RADIUS | RADIUS.Acct-Username (obligatoire) RADIUS.Acct-NAS-IP-Address RADIUS.Acct-NAS-Port RADIUS.Acct-NAS-Port-Type RADIUS.Acct-Calling-Station-Id RADIUS.Acct-Framed-IP-Address RADIUS.Acct-Session-Id (obligatoire) RADIUS.Acct-Session-Time RADIUS.Acct-Output-Pkts RADIUS.Acct-Input-Pkts RADIUS.Acct-Output-Octets RADIUS.Acct-Input.Octets RADIUS.Acct-Service-Name RADIUS.Acct-Timestamp (obligatoire) |
| Journaux de session | tacacs+ Administration | Common.Username Common.Service tacacs.Remote-Address (obligatoire) tacacs.Privilege.Level (obligatoire) Common.Request-Timestamp |
| Journaux de session | tacacs+ Accounting | Common.Username Common.Service tacacs.Remote-Address (obligatoire) tacacs.Acct-Flags (obligatoire) tacacs.Privilege.Level (obligatoire) Common.Request-Timestamp |
| Journaux de session | Authentification Web | Common.Username Common.Host-MAC-Address WEBAUTH.Host-IP-Address (obligatoire) Common.Roles Common.System-Posture-Token Common.Enforcement-Profiles Common.Request-Timestamp |
| Journaux de session | Accès invité | Common.Username (obligatoire) RADIUS.Auth-Method Common.Host-MAC-Address Common.Roles Common.System-Posture-Token Common.Enforcement-Profiles Common.Request-Timestamp |
| Journaux de session | Accès invité réussi | Common.Username (obligatoire) Common.Error-Code = 0 (obligatoire) Common.Service Common.Host-MAC-Address Common.NAS-IP-Address Common.Request-Timestamp Common.System-Posture-Token Common.Enforcement-Profiles Common.Alerts |
| Journaux de session | Accès réseau | Common.Username (obligatoire) Common.Roles (obligatoire) Common.Service Common.Host-MAC-Address Common.Request-Timestamp Common.System-Posture-Token Common.Enforcement-Profiles Common.Alerts |
| Journaux de session | Accès au réseau réussi | Common.Username (obligatoire) Common.Roles (obligatoire) Common.Error-Code = 0 (obligatoire) Common.Service Common.Host-MAC-Address Common.NAS-IP-Address Common.Request-Timestamp Common.System-Posture-Token Common.Enforcement-Profiles Common.Alerts |
| Journaux de session | Authentification MAC | Common.Service (Doit contenir le mot-clé « mac-authentication ») Common.Username Common.Roles Common.Host-MAC-Address Common.NAS-IP-Address Common.Request-Timestamp |
| Journaux de session | Authentification SSID | Common.Service (Doit contenir « SSID » OU « authentification ») Common.Username Common.Request-Timestamp Common.Error-Code |
| Journaux de session | Échec de l'authentification SSID | Common.Service (Doit contenir « SSID » OU « authentification ») Common.Error-Code > 0 (obligatoire) Common.Username Common.Request-Timestamp Common.Error-Code |
Procédure
- Connectez-vous à votre serveur Aruba ClearPass Policy Manager.
- Démarrez la console d'administration.
- Cliquez sur .
- Cliquez sur Ajouter, puis configurez les détails de l'hôte QRadar .
- Dans la console d'administration, cliquez sur
- Cliquez sur Ajouter.
- Sélectionnez LEEF pour Exporter le type de format d'événement, puis sélectionnez le Serveur Syslog que vous avez ajouté.
- Cliquez sur Sauvegarder.