Illumio Adaptive Security Platform

The IBM® QRadar® DSM for Illumio Adaptive Security Platform collects events from the Illumio Policy Compute Engine (PCE).

The following table describes the specifications for the Illumio Adaptive Security Platform DSM:
Table 1. Illumio Adaptive Security Platform DSM specifications
Specification Value
Manufacturer Illumio
DSM name Illumio Adaptive Security Platform
RPM file name DSM-IllumioAdaptiveSecurityPlatform-QRadar_version-build_number.noarch.rpm
Supported versions N/A
Protocol Syslog
Event format Log Event Extended Format (LEEF)
Recorded event types

Audit

Traffic

Automatically discovered? Yes
Includes identity? No
Includes custom properties? No
More information Illumio website (https://www.illumio.com)
To integrate Illumio Adaptive Security Platform with QRadar, complete the following steps:
  1. If automatic updates are not enabled, download and install the most recent version of the following RPMs from the IBM Support Website onto, in the order that they are listed, on your QRadar Console:
    • DSMCommon RPM
    • Illumio Adaptive Security Platform DSM RPM
  2. Configure your Illumio PCE to send syslog events to QRadar.
  3. If QRadar does not automatically detect the log source, add an Illumio Adaptive Security Platform log source on the QRadar Console. The following table describes the parameters that require specific values for Illumio Adaptive Security Platform event collection:
    Table 2. Illumio Adaptive Security Platform log source parameters
    Parameter Value
    Log Source type Illumio Adaptive Security Platform
    Protocol Configuration Syslog
    Log Source Identifier A unique identifier for the log source.
  4. To verify that QRadar is configured correctly, review the following table to see an example of a parsed event message.
    Important: Due to formatting issues, paste the message format into a text editor and then remove any carriage return or line feed characters.
    The following table shows a sample event message from Illumio Adaptive Security Platform:
    Table 3. Illumio Adaptive Security Platform sample message
    Event name Low level category Sample log message
    flow_allowed Firewall Permit
    <14>1 2016-08-08T22:18:24.000+00:00 hostname1 illumio_pce/collector 5458 - - sec=694704.253 sev=INFO  pid=5458 tid=14554040 rid=0 LEEF:2.0|Illumio|PCE|16.6.0|flow_allowed|cat=flow_summary	devTime=2016-08-08T15:20:55-07:00	devTimeFormat=yyyy-MM-dd'T'HH:mm:ssX	proto=udp	sev=1	src=<Source_IP_address>	dst=<Destination_IP_address>	dstPort=14000	srcBytes=0	dstBytes=15936	count=1	dir=I	hostname=hostname2	intervalSec=3180	state=T	workloadUUID=xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx