QRadar 와 통신하도록 Aruba ClearPass 정책 관리자 구성
Aruba ClearPass Policy Manager에서 syslog 이벤트를 수집하려면 IBM QRadar 호스트에 대한 외부 syslog 서버를 추가한 후 syslog 서버에 대한 하나 이상의 syslog 필터를 작성해야 합니다.
이 태스크에 대한 정보
다음 표에서는 사용할 수 있는 필드 카테고리 및 해당 기본 필드를 표시합니다.
| 템플릿 내보내기 | 사전 정의된 필드 그룹 | 기본 선택 열 |
|---|---|---|
| Insight 로그 | Radius 인증 | Auth.Username (필수) Auth.Host-MAC-Address Auth.Protocol = RADIUS (필수) Auth.NAS-IP-Address CppmNodeCPPM-노드 Auth.Login-Status Auth.Service Auth.Roles Auth.Enforcement-Profiles |
| Insight 로그 | Radius 실패한 인증 | Auth.Username (필수) Auth.Host-MAC-Address Auth.NAS-IP-Address CppmNodeCPPM-노드 Auth.Service CppmErrorCode.Error-Code-Details (필수) CppmAlert경보 |
| Insight 로그 | Radius 회계 | Radius.Username (필수) Radius.Calling-Station-Id Radius.Framed-IP-Address Radius.NAS-IP-Address Radius.Start-Time (필수) Radius.End-Time Radius.Duration (필수) Radius.Input-bytes Radius.Output-bytes |
| Insight 로그 | TACACS 인증 | tacacs.Username (필수) tacacs.Remote-Address tacacs.Request-Type tacacs.NAS-IP-Address tacacs.Service tacacs.Auth-Source tacacs.Roles tacacs.Enforcement-Profiles tacacs.Privilege-Level |
| Insight 로그 | TACAS 인증 성공 | tacacs.Username (필수) TACACS.Error-code (필수) Comma.Login-Status Tacacs.Roles |
| Insight 로그 | tacacs 실패한 인증 | tacacs.Username (필수) tacacs.Remote-Address tacacs.Request-Type tacacs.NAS-IP-Address tacacs.Service CppmErrorCode.Error-Code-Details TACACS.Error-code (필수) CppmAlert경보 |
| Insight 로그 | 애플리케이션 인증 | Auth.Username (필수) Auth.Host-IP-Address (필수) Auth.Protocol (필수) CppmNodeCPPM-노드 Auth.Login-Status Auth.Service Auth.Source Auth.Roles Auth.Enforcement-Profiles |
| Insight 로그 | 실패한 애플리케이션 인증 | Auth.Username (필수) Auth.Host-IP-Address (필수) Auth.Protocol (필수) CppmNodeCPPM-노드 Auth.Login-Status Auth.Service CppmErrorCode.Error-Code-Details (필수) CppmAlert경보 |
| Insight 로그 | 엔드포인트 | Endpoint.MAC-Address (필수) Endpoint.MAC-Vendor Endpoint.IP-Address Endpoint.Username Endpoint.Device-Category Endpoint.Device-Family Endpoint.Device-Name Endpoint.Conflict Endpoint.Status Endpoint.Added-At Endpoint.Updated-At |
| Insight 로그 | Clearpass 게스트 | Guest.Username (필수) Guest.MAC-Address Guest.Visitor-Name Guest.Visitor-Company Guest.Role-Name Guest.Enabled Guest.Created-At Guest.Starts-At Guest.Expires-At |
| Insight 로그 | 온보드 등록 | OnboardEnrollment.Username (필수) OnboardEnrollment디바이스-이름 OnboardEnrollmentMAC-주소 OnboardEnrollment디바이스-제품 OnboardEnrollment디바이스-버전 OnboardEnrollment추가 시간 OnboardEnrollment업데이트 시간 |
| Insight 로그 | 온보드 인증서 | OnboardCert.Username (필수) OnboardCert.Mac-주소 OnboardCert.Subject OnboardCert.발행자 OnboardCert.유효 시작 OnboardCert.유효 종료 날짜 OnboardCert.취소 시간 |
| Insight 로그 | 온보드 OCSP | OnboardOCSP.Remote-Address (필수) OnboardOCSP응답-상태-이름 OnboardOCSP시간소인 |
| Insight 로그 | Clearpass 시스템 이벤트 | CppmNodeCPPM-노드 CppmSystemEvent.Source (필수) CppmSystemEvent.Level CppmSystemEvent.Category CppmSystemEvent.Action CppmSystemEvent.Timestamp |
| Insight 로그 | Clearpass 구성 감사 | CppmConfigAudit.Name (필수) CppmConfigAudit.Action CppmConfigAudit.Category CppmConfigAudit.Updated-By CppmConfigAudit.Updated-At |
| Insight 로그 | 자세 요약 | Endpoint.MAC-Address Endpoint.IP-Address Endpoint.Hostname Endpoint.Usermame Endpoint.System-Agent-Type Endpoint.System-Agent-Version Endpoint.System-Client-OS Endpoint.System-Posture-Token (필수) Endpoint.Posture-Healthy Endpoint.Posture-Unhealthy |
| Insight 로그 | 방화벽 상태 요약 | Endpoint.MAC-Address (필수) Endpoint.IP-Address Endpoint.Hostname Endpoint.Usermame Endpoint.System-Agent-Type Endpoint.System-Agent-Version Endpoint.System-Client-OS Endpoint.System-Posture-Token Endpoint.Firewall-APT (필수) Endpoint.Firewall-Input Endpoint.Firewall-Output |
| Insight 로그 | 바이러스 백신 상태 요약 | Endpoint.MAC-Address (필수) Endpoint.IP-Address Endpoint.Hostname Endpoint.Usermame Endpoint.System-Agent-Type Endpoint.System-Agent-Version Endpoint.System-Client-OS Endpoint.System-Posture-Token Endpoint.Antivirus-APT (필수) Endpoint.Antivirus-Input 제공합니다. 안티바이러스-출력 |
| Insight 로그 | 자세 안티스파이웨어 요약 | Endpoint.MAC-Address (필수) Endpoint.IP-Address Endpoint.Hostname Endpoint.Usermame Endpoint.System-Agent-Type Endpoint.System-Agent-Version Endpoint.System-Client-OS Endpoint.System-Posture-Token Endpoint.Antispyware-APT (필수) Endpoint.Antispyware-Input Endpoint.Antispyware-Output |
| Insight 로그 | 자세 DiskEncryption 요약 | Endpoint.MAC-Address (필수) Endpoint.IP-Address Endpoint.Hostname Endpoint.Usermame Endpoint.System-Agent-Type Endpoint.System-Agent-Version Endpoint.System-Client-OS Endpoint.System-Posture-Token Endpoint.DiskEncryption-APT (필수) Endpoint.DiskEncryption-Input Endpoint.DiskEncryption-Output |
| Insight 로그 | 상태 Windows 핫픽스 요약 | Endpoint.MAC-Address (필수) Endpoint.IP-Address Endpoint.Hostname Endpoint.Usermame Endpoint.System-Agent-Type Endpoint.System-Agent-Version Endpoint.System-Client-OS Endpoint.System-Posture-Token Endpoint.HotFixes-APT (필수) Endpoint.HotFixes-Input Endpoint.HotFixes-Output |
| 세션 로그 | 로그인한 사용자 | Common.Username (필수) Common.Service (필수) Common.Roles Common.Host-MAC-Address (필수) RADIUS.Acct-Framed-IP-Address (필수) Common.NAS-IP-Address Common.Request-Timestamp |
| 세션 로그 | 실패한 인증 | Common.Username (필수) Common.Service (필수) Common.Roles RADIUS.Auth-Source RADIUS.Auth-Method Common.System-Posture-Token Common.Enforcement-Profiles Common.Host-MAC-Address (필수) Common.NAS-IP-Address Common.Error-Code (필수) Common.Alerts Common.Request-Timestamp |
| 세션 로그 | Radius 회계 | RADIUS.Acct-Username (필수) RADIUS.Acct-NAS-IP-Address RADIUS.Acct-NAS-Port RADIUS.Acct-NAS-Port-Type RADIUS.Acct-Calling-Station-Id RADIUS.Acct-Framed-IP-Address RADIUS.Acct-Session-Id (필수) RADIUS.Acct-Session-Time RADIUS.Acct-Output-Pkts RADIUS.Acct-Input-Pkts RADIUS.Acct-Output-Octets RADIUS.Acct-Input.Octets RADIUS.Acct-Service-Name RADIUS.Acct-Timestamp (필수) |
| 세션 로그 | tacacs+관리 | Common.Username Common.Service tacacs.Remote-Address (필수) tacacs.Privilege.Level (필수) Common.Request-Timestamp |
| 세션 로그 | Tacacs+회계 | Common.Username Common.Service tacacs.Remote-Address (필수) tacacs.Acct-Flags (필수) tacacs.Privilege.Level (필수) Common.Request-Timestamp |
| 세션 로그 | 웹 인증 | Common.Username Common.Host-MAC-Address WEBAUTH.Host-IP-Address (필수) Common.Roles Common.System-Posture-Token Common.Enforcement-Profiles Common.Request-Timestamp |
| 세션 로그 | 게스트 액세스 | Common.Username (필수) RADIUS.Auth-Method Common.Host-MAC-Address Common.Roles Common.System-Posture-Token Common.Enforcement-Profiles Common.Request-Timestamp |
| 세션 로그 | 게스트 접속 성공 | Common.Username (필수) Common.Error-Code = 0 (필수) Common.Service Common.Host-MAC-Address Common.NAS-IP-Address Common.Request-Timestamp Common.System-Posture-Token Common.Enforcement-Profiles Common.Alerts |
| 세션 로그 | 네트워크 액세스 | Common.Username (필수) Common.Roles (필수) Common.Service Common.Host-MAC-Address Common.Request-Timestamp Common.System-Posture-Token Common.Enforcement-Profiles Common.Alerts |
| 세션 로그 | 네트워크 접속 성공 | Common.Username (필수) Common.Roles (필수) Common.Error-Code = 0 (필수) Common.Service Common.Host-MAC-Address Common.NAS-IP-Address Common.Request-Timestamp Common.System-Posture-Token Common.Enforcement-Profiles Common.Alerts |
| 세션 로그 | MAC 인증 | Common.Service (키워드 "mac-authentication"을 반드시 포함해야 함) Common.Username Common.Roles Common.Host-MAC-Address Common.NAS-IP-Address Common.Request-Timestamp |
| 세션 로그 | SSID 인증 | Common.Service (SSID 또는 인증을 반드시 포함해야 함) Common.Username Common.Request-Timestamp Common.Error-Code |
| 세션 로그 | SSID 인증 실패 | Common.Service (SSID 또는 인증을 반드시 포함해야 함) Common.Error-Code > 0 (필수) Common.Username Common.Request-Timestamp Common.Error-Code |
프로시저
- Aruba Clearpass 정책 관리자 서버에 로그인하십시오.
- 관리 콘솔을 시작하십시오.
- 클릭.
- 추가를 클릭한 후 QRadar 호스트의 세부사항을 구성하십시오.
- 관리 콘솔에서 클릭합니다.
- 추가를 클릭하십시오.
- 내보내기 이벤트 형식 유형에 대해 LEEF 를 선택한 후 추가한 Syslog 서버 를 선택하십시오.
- 저장을 클릭하십시오.