Syslog - Aruba Clear Pass (2024)

Device Details

Device NameAruba Clear Pass

Vendor

Aruba

Device Type

Policy Management Platform

Supported Model Name/Number

N/A

Supported Software Version(s)

N/A

Collection Method

Syslog

Configurable Log Output?

N/A

Log Source Type

Syslog – Aruba Clear Pass

Log Processing Policy

LogRhythm Default

Exceptions

N/A

Additional Information

Adding a Syslog Target – Aruba

https://www.arubanetworks.com/techdocs/ClearPass/6.7/PolicyManager/Content/CPPM_UserGuide/Admin/syslogTargets.html#addSylogTarget1058

Adding a Syslog Export Filter – Aruba

https://www.arubanetworks.com/techdocs/ClearPass/6.7/PolicyManager/Content/CPPM_UserGuide/Admin/syslogExportFilters_add_syslog_filter_general.htm

Prerequisites

  • Access to Aruba Clear Pass platform.
  • Port 514 TCP/UDP allowed from Aruba Clear Pass to LogRhythm System Monitor Agent.
  • Port 514 TCP/UDP allowed on LogRhythm System Monitor Agent to receive syslog packets from Aruba Clear Pass.
  • LogRhythm Global Admins or Restricted Admins with elevated View and Manage privileges.

Configure Aruba Clear Pass

Add a Syslog Target

To add a syslog target:

  1. Click Administration, and then External Servers.
  2. Click Syslog Targets.
    The Syslog Targets page opens.
  3. Click Add.
    TheAdd Syslog Targetdialog opens.
  4. Specify the following Add Syslog Target parameters:

    ParameterDescription
    Host AddressEnter the syslog server hostname or IP address.
    DescriptionEnter a short description of the syslog server.
    ProtocolSelect either TCP or UDP.
    Server PortThe default port number is 514.
  5. Click Save.
    The new Syslog Target is added to the list.

Add a Syslog Export Filter

To add a syslog export filter:

  1. Click Administration, and thenExternal Servers.
  2. Click Syslog Export Filters.
  3. Click Add.
    The Add Syslog Filterspage opens to theGeneraltab.
  4. Specify the following:

    ParameterDescription
    Name

    Name of the syslog export filter.

    DescriptionEnter a short description for the syslog export filter.
    Export Event Format TypeSelectStandardto use the default event format.
    Syslog ServersDefine the receivers of syslog messages using theSelect to Adddrop-list.
  5. ClickSave.

Configure LogRhythm

Only Global Admins or Restricted Admins with elevated View and Manage privileges can take these actions.

Confirm the Syslog Server is Enabled

  1. In the Client Console on the main toolbar, clickDeployment Manager.
  2. Click theSystem Monitorstab.
  3. Double-click the System Monitor Agent that collects the logs.
    The System Monitor Agent Properties dialog box appears.
  4. Click theSyslog and Flow Settingstab.
  5. Click theEnable Syslog Servercheck box.
  6. ClickOK.

Restart the LogRhythm System Monitor Service

  1. On the System Monitor Agent host, right-click the Windows Startmenu, and then clickRun.
    The Run dialog box appears.
  2. In the Open field, enterservices.msc, and then click OK.
    The Services console appears.
  3. Right-click LogRhythm System Monitor Service, and then clickRestart.

Verify the System Monitor Agent is Connected

After restarting the LogRhythm System Monitor Service, you need to verify that the Agent is listening for the TCP/UDP connection on default port 514.

  1. On the System Monitor Agent host, right-click the Windows Startmenu, and then clickCommand Prompt.
    The Command Prompt dialog box appears.
  2. Execute the following command:

    POWERSHELL

    netstat -ano | findstr :514

    Example of expected output:

    Syslog - Aruba Clear Pass (1)

Syslog - Aruba Clear Pass (2)

Ensure that the firewall on the Agent machine is allowing the incoming connection over TCP/UDP on port 514.

Configure LogRhythm to Collect Logs

Resolve Log Source Hosts

  1. On the main toolbar, clickDeployment Manager.
  2. Click theLog Sourcestab.
  3. In the New Log Sources grid, select theActioncheck box of the Syslog – Aruba Clear Pass log source.
  4. Right-click the selection, clickActions, and then clickResolve Log Source Hosts.
    The Resolve Known Hosts Complete dialog box appears.
  5. ClickOK.

Confirm Log Source Acceptance Properties

  1. On the main toolbar, clickDeployment Manager.
  2. Click theLog Sourcestab.
  3. In the New Log Sources grid, select theActioncheck box of the Syslog – Aruba Clear Pass log source.
  4. Right-click the selection,and then clickProperties.
    The Log Source Acceptance Properties dialog box appears.
  5. Confirm the Device IP Address matches the IP address of the Aruba Clear Pass device.
  6. (Optional)Change the Log Source Name, if desired.
  7. To the right of the Log Source Type field, click the...selector.
    The Log Source Type Selector dialog box appears.
  8. In the Text Filter field, enterSyslog – Aruba Clear Pass, and then clickApply.
  9. In the Log Source Type section, clickSystem : Syslog - Aruba Clear Pass, and then clickOK.
    The Log Source Acceptance Properties dialog box appears.
  10. Click the field under MPE Policy, and then clickLogRhythm Default.
  11. ClickOK.

Accept the New Log Source

  1. On the main toolbar, clickDeployment Manager.
  2. Click theLog Sourcestab.
  3. In the New Log Sources grid, select theActioncheck box of the Syslog – Aruba Clear Pass.
  4. Right-click the selection, clickActions, clickAccept, and then clickDefaults.
    The Accept Successful dialog box appears.
  5. ClickOK.
    The Syslog – Aruba Clear Pass Log source moves from the New Log Sources list to the existing list in at the bottom of the screen.

Tail the Log Source

  1. On the main toolbar, clickDeployment Manager.
  2. Click theLog Sourcestab.
  3. In the grid below the New Log Sources grid, select theActioncheck box of the Syslog – Aruba Clear Pass log source.
  4. Right-click the selection, clickActions, and then clickTail Log Source(s).
Syslog - Aruba Clear Pass (2024)
Top Articles
Frequently asked questions (FAQ) about pepper spray | Zarc
Why should you carry pepper spray? – American Contingency
#ridwork guides | fountainpenguin
Time in Baltimore, Maryland, United States now
Dte Outage Map Woodhaven
O'reilly's Auto Parts Closest To My Location
Stadium Seats Near Me
Paris 2024: Kellie Harrington has 'no more mountains' as double Olympic champion retires
Jefferey Dahmer Autopsy Photos
Gabrielle Abbate Obituary
Zitobox 5000 Free Coins 2023
Craigslist Dog Sitter
Flat Twist Near Me
Over70Dating Login
Tcu Jaggaer
Best Fare Finder Avanti
Bowie Tx Craigslist
Uc Santa Cruz Events
boohoo group plc Stock (BOO) - Quote London S.E.- MarketScreener
Dtab Customs
Dirt Removal in Burnet, TX ~ Instant Upfront Pricing
Palm Springs Ca Craigslist
Kountry Pumpkin 29
Satisfactory: How to Make Efficient Factories (Tips, Tricks, & Strategies)
/Www.usps.com/International/Passports.htm
Schedule An Oil Change At Walmart
Okc Body Rub
Finding Safety Data Sheets
Tokyo Spa Memphis Reviews
Account Now Login In
Studentvue Calexico
Robotization Deviantart
Frequently Asked Questions - Hy-Vee PERKS
Arcane Odyssey Stat Reset Potion
Usf Football Wiki
Kazwire
Final Fantasy 7 Remake Nexus
Gateway Bible Passage Lookup
Aurora Il Back Pages
Gt500 Forums
Cuckold Gonewildaudio
Uc Davis Tech Management Minor
Random Animal Hybrid Generator Wheel
Unit 11 Homework 3 Area Of Composite Figures
Big Brother 23: Wiki, Vote, Cast, Release Date, Contestants, Winner, Elimination
300+ Unique Hair Salon Names 2024
Latina Webcam Lesbian
Raley Scrubs - Midtown
Round Yellow Adderall
4015 Ballinger Rd Martinsville In 46151
Latest Posts
Article information

Author: Kelle Weber

Last Updated:

Views: 6597

Rating: 4.2 / 5 (53 voted)

Reviews: 84% of readers found this page helpful

Author information

Name: Kelle Weber

Birthday: 2000-08-05

Address: 6796 Juan Square, Markfort, MN 58988

Phone: +8215934114615

Job: Hospitality Director

Hobby: tabletop games, Foreign language learning, Leather crafting, Horseback riding, Swimming, Knapping, Handball

Introduction: My name is Kelle Weber, I am a magnificent, enchanting, fair, joyous, light, determined, joyous person who loves writing and wants to share my knowledge and understanding with you.