QRadar 와 통신하도록 Aruba ClearPass 정책 관리자 구성

Aruba ClearPass Policy Manager에서 syslog 이벤트를 수집하려면 IBM QRadar 호스트에 대한 외부 syslog 서버를 추가한 후 syslog 서버에 대한 하나 이상의 syslog 필터를 작성해야 합니다.

이 태스크에 대한 정보

세션 및 Insight ® 이벤트의 경우 전체 이벤트 구문 분석은 Aruba ClearPass 정책 관리자가 제공하는 기본 필드에 대해서만 작동합니다. 사용자가 작성하고 서로 다른 필드 조합이 있는 세션 및 Insight 이벤트는 알 수 없는 세션 로그또는 알 수 없는 Insight 로그로 표시될 수 있습니다.

다음 표에서는 사용할 수 있는 필드 카테고리 및 해당 기본 필드를 표시합니다.

표 1. Aruba ClearPass Policy Manager에서 제공하는 세션 및 Insight 이벤트의 기본 카테고리 및 필드
템플릿 내보내기 사전 정의된 필드 그룹 기본 선택 열
Insight 로그 Radius 인증

Auth.Username (필수)

Auth.Host-MAC-Address

Auth.Protocol = RADIUS (필수)

Auth.NAS-IP-Address

CppmNodeCPPM-노드

Auth.Login-Status

Auth.Service

Auth.Roles

Auth.Enforcement-Profiles

Insight 로그 Radius 실패한 인증

Auth.Username (필수)

Auth.Host-MAC-Address

Auth.NAS-IP-Address

CppmNodeCPPM-노드

Auth.Service

CppmErrorCode.Error-Code-Details (필수)

CppmAlert경보

Insight 로그 Radius 회계

Radius.Username (필수)

Radius.Calling-Station-Id

Radius.Framed-IP-Address

Radius.NAS-IP-Address

Radius.Start-Time (필수)

Radius.End-Time

Radius.Duration (필수)

Radius.Input-bytes

Radius.Output-bytes

Insight 로그 TACACS 인증

tacacs.Username (필수)

tacacs.Remote-Address

tacacs.Request-Type

tacacs.NAS-IP-Address

tacacs.Service

tacacs.Auth-Source

tacacs.Roles

tacacs.Enforcement-Profiles

tacacs.Privilege-Level

Insight 로그 TACAS 인증 성공

tacacs.Username (필수)

TACACS.Error-code (필수)

Comma.Login-Status

Tacacs.Roles

Insight 로그 tacacs 실패한 인증

tacacs.Username (필수)

tacacs.Remote-Address

tacacs.Request-Type

tacacs.NAS-IP-Address

tacacs.Service

CppmErrorCode.Error-Code-Details

TACACS.Error-code (필수)

CppmAlert경보

Insight 로그 애플리케이션 인증

Auth.Username (필수)

Auth.Host-IP-Address (필수)

Auth.Protocol (필수)

CppmNodeCPPM-노드

Auth.Login-Status

Auth.Service

Auth.Source

Auth.Roles

Auth.Enforcement-Profiles

Insight 로그 실패한 애플리케이션 인증

Auth.Username (필수)

Auth.Host-IP-Address (필수)

Auth.Protocol (필수)

CppmNodeCPPM-노드

Auth.Login-Status

Auth.Service

CppmErrorCode.Error-Code-Details (필수)

CppmAlert경보

Insight 로그 엔드포인트

Endpoint.MAC-Address (필수)

Endpoint.MAC-Vendor

Endpoint.IP-Address

Endpoint.Username

Endpoint.Device-Category

Endpoint.Device-Family

Endpoint.Device-Name

Endpoint.Conflict

Endpoint.Status

Endpoint.Added-At

Endpoint.Updated-At

Insight 로그 Clearpass 게스트

Guest.Username (필수)

Guest.MAC-Address

Guest.Visitor-Name

Guest.Visitor-Company

Guest.Role-Name

Guest.Enabled

Guest.Created-At

Guest.Starts-At

Guest.Expires-At

Insight 로그 온보드 등록

OnboardEnrollment.Username (필수)

OnboardEnrollment디바이스-이름

OnboardEnrollmentMAC-주소

OnboardEnrollment디바이스-제품

OnboardEnrollment디바이스-버전

OnboardEnrollment추가 시간

OnboardEnrollment업데이트 시간

Insight 로그 온보드 인증서

OnboardCert.Username (필수)

OnboardCert.Mac-주소

OnboardCert.Subject

OnboardCert.발행자

OnboardCert.유효 시작

OnboardCert.유효 종료 날짜

OnboardCert.취소 시간

Insight 로그 온보드 OCSP

OnboardOCSP.Remote-Address (필수)

OnboardOCSP응답-상태-이름

OnboardOCSP시간소인

Insight 로그 Clearpass 시스템 이벤트

CppmNodeCPPM-노드

CppmSystemEvent.Source (필수)

CppmSystemEvent.Level

CppmSystemEvent.Category

CppmSystemEvent.Action

CppmSystemEvent.Timestamp

Insight 로그 Clearpass 구성 감사

CppmConfigAudit.Name (필수)

CppmConfigAudit.Action

CppmConfigAudit.Category

CppmConfigAudit.Updated-By

CppmConfigAudit.Updated-At

Insight 로그 자세 요약

Endpoint.MAC-Address

Endpoint.IP-Address

Endpoint.Hostname

Endpoint.Usermame

Endpoint.System-Agent-Type

Endpoint.System-Agent-Version

Endpoint.System-Client-OS

Endpoint.System-Posture-Token (필수)

Endpoint.Posture-Healthy

Endpoint.Posture-Unhealthy

Insight 로그 방화벽 상태 요약

Endpoint.MAC-Address (필수)

Endpoint.IP-Address

Endpoint.Hostname

Endpoint.Usermame

Endpoint.System-Agent-Type

Endpoint.System-Agent-Version

Endpoint.System-Client-OS

Endpoint.System-Posture-Token

Endpoint.Firewall-APT (필수)

Endpoint.Firewall-Input

Endpoint.Firewall-Output

Insight 로그 바이러스 백신 상태 요약

Endpoint.MAC-Address (필수)

Endpoint.IP-Address

Endpoint.Hostname

Endpoint.Usermame

Endpoint.System-Agent-Type

Endpoint.System-Agent-Version

Endpoint.System-Client-OS

Endpoint.System-Posture-Token

Endpoint.Antivirus-APT (필수)

Endpoint.Antivirus-Input

제공합니다. 안티바이러스-출력

Insight 로그 자세 안티스파이웨어 요약

Endpoint.MAC-Address (필수)

Endpoint.IP-Address

Endpoint.Hostname

Endpoint.Usermame

Endpoint.System-Agent-Type

Endpoint.System-Agent-Version

Endpoint.System-Client-OS

Endpoint.System-Posture-Token

Endpoint.Antispyware-APT (필수)

Endpoint.Antispyware-Input

Endpoint.Antispyware-Output

Insight 로그 자세 DiskEncryption 요약

Endpoint.MAC-Address (필수)

Endpoint.IP-Address

Endpoint.Hostname

Endpoint.Usermame

Endpoint.System-Agent-Type

Endpoint.System-Agent-Version

Endpoint.System-Client-OS

Endpoint.System-Posture-Token

Endpoint.DiskEncryption-APT (필수)

Endpoint.DiskEncryption-Input

Endpoint.DiskEncryption-Output

Insight 로그 상태 Windows 핫픽스 요약

Endpoint.MAC-Address (필수)

Endpoint.IP-Address

Endpoint.Hostname

Endpoint.Usermame

Endpoint.System-Agent-Type

Endpoint.System-Agent-Version

Endpoint.System-Client-OS

Endpoint.System-Posture-Token

Endpoint.HotFixes-APT (필수)

Endpoint.HotFixes-Input

Endpoint.HotFixes-Output

세션 로그 로그인한 사용자

Common.Username (필수)

Common.Service (필수)

Common.Roles

Common.Host-MAC-Address (필수)

RADIUS.Acct-Framed-IP-Address (필수)

Common.NAS-IP-Address

Common.Request-Timestamp

세션 로그 실패한 인증

Common.Username (필수)

Common.Service (필수)

Common.Roles

RADIUS.Auth-Source

RADIUS.Auth-Method

Common.System-Posture-Token

Common.Enforcement-Profiles

Common.Host-MAC-Address (필수)

Common.NAS-IP-Address

Common.Error-Code (필수)

Common.Alerts

Common.Request-Timestamp

세션 로그 Radius 회계

RADIUS.Acct-Username (필수)

RADIUS.Acct-NAS-IP-Address

RADIUS.Acct-NAS-Port

RADIUS.Acct-NAS-Port-Type

RADIUS.Acct-Calling-Station-Id

RADIUS.Acct-Framed-IP-Address

RADIUS.Acct-Session-Id (필수)

RADIUS.Acct-Session-Time

RADIUS.Acct-Output-Pkts

RADIUS.Acct-Input-Pkts

RADIUS.Acct-Output-Octets

RADIUS.Acct-Input.Octets

RADIUS.Acct-Service-Name

RADIUS.Acct-Timestamp (필수)

세션 로그 tacacs+관리

Common.Username

Common.Service

tacacs.Remote-Address (필수)

tacacs.Privilege.Level (필수)

Common.Request-Timestamp

세션 로그 Tacacs+회계

Common.Username

Common.Service

tacacs.Remote-Address (필수)

tacacs.Acct-Flags (필수)

tacacs.Privilege.Level (필수)

Common.Request-Timestamp

세션 로그 웹 인증

Common.Username

Common.Host-MAC-Address

WEBAUTH.Host-IP-Address (필수)

Common.Roles

Common.System-Posture-Token

Common.Enforcement-Profiles

Common.Request-Timestamp

세션 로그 게스트 액세스

Common.Username (필수)

RADIUS.Auth-Method

Common.Host-MAC-Address

Common.Roles

Common.System-Posture-Token

Common.Enforcement-Profiles

Common.Request-Timestamp

세션 로그 게스트 접속 성공

Common.Username (필수)

Common.Error-Code = 0 (필수)

Common.Service

Common.Host-MAC-Address

Common.NAS-IP-Address

Common.Request-Timestamp

Common.System-Posture-Token

Common.Enforcement-Profiles

Common.Alerts

세션 로그 네트워크 액세스

Common.Username (필수)

Common.Roles (필수)

Common.Service

Common.Host-MAC-Address

Common.Request-Timestamp

Common.System-Posture-Token

Common.Enforcement-Profiles

Common.Alerts

세션 로그 네트워크 접속 성공

Common.Username (필수)

Common.Roles (필수)

Common.Error-Code = 0 (필수)

Common.Service

Common.Host-MAC-Address

Common.NAS-IP-Address

Common.Request-Timestamp

Common.System-Posture-Token

Common.Enforcement-Profiles

Common.Alerts

세션 로그 MAC 인증 Common.Service (키워드 "mac-authentication"을 반드시 포함해야 함)

Common.Username

Common.Roles

Common.Host-MAC-Address

Common.NAS-IP-Address

Common.Request-Timestamp

세션 로그 SSID 인증 Common.Service (SSID 또는 인증을 반드시 포함해야 함)

Common.Username

Common.Request-Timestamp

Common.Error-Code

세션 로그 SSID 인증 실패

Common.Service (SSID 또는 인증을 반드시 포함해야 함)

Common.Error-Code > 0 (필수)

Common.Username

Common.Request-Timestamp

Common.Error-Code

프로시저

  1. Aruba Clearpass 정책 관리자 서버에 로그인하십시오.
  2. 관리 콘솔을 시작하십시오.
  3. 외부 서버 > 시스로그 대상 클릭.
  4. 추가를 클릭한 후 QRadar 호스트의 세부사항을 구성하십시오.
  5. 관리 콘솔에서 외부 서버 > 시스로그 내보내기 필터를 클릭합니다.
  6. 추가를 클릭하십시오.
  7. 내보내기 이벤트 형식 유형에 대해 LEEF 를 선택한 후 추가한 Syslog 서버 를 선택하십시오.
  8. 저장을 클릭하십시오.