Skip to content

Aruba ClearPass

Overview

Aruba ClearPass is a vendor-agnostic network access control (NAC) and policy management platform by HPE Aruba Networking that automates security compliance and role-based access for all users, devices, and IoT endpoints.

  • Vendor: Aruba Networks
  • Supported environment: On-Prem
  • Detection based on: Telemetry

Configure

Instructions on Sekoia

Configure Your Intake

This section will guide you through creating the intake object in Sekoia, which provides a unique identifier called the "Intake key." The Intake key is essential for later configuration, as it references the Community, Entity, and Parser (Intake Format) used when receiving raw events on Sekoia.

  1. Go to the Sekoia Intake page.
  2. Click on the + New Intake button at the top right of the page.
  3. Search for your Intake by the product name in the search bar.
  4. Give it a Name and associate it with an Entity (and a Community if using multi-tenant mode).
  5. Click on Create.

Note

For more details on how to use the Intake page and to find the Intake key you just created, refer to this documentation.

Configure a forwarder

To forward events using syslog to Sekoia.io, you need to update the syslog header with the intake key you previously created. Here is an example of your message before the forwarder

<%pri%>1 %timestamp:::date-rfc3339% %hostname% %app-name% %procid% LOG RAW_MESSAGE
and after
<%pri%>1 %timestamp:::date-rfc3339% %hostname% %app-name% %procid% LOG [SEKOIA@53288 intake_key=\"YOUR_INTAKE_KEY\"] RAW_MESSAGE

To achieve this you can:

  • Use the Sekoia.io forwarder which is the official supported way to collect data using the syslog protocol in Sekoia.io. In charge of centralizing data coming from many equipments/sources and forwarding them to Sekoia.io with the apporpriated format, it is a prepackaged option. You only have to provide your intake key as parameter.
  • Use your own Syslog service instance. Maybe you already have an intance of one of these components on your side and want to reuse it in order to centralize data before forwarding them to Sekoia.io. When using this mode, you have to configure and maintain your component in order to respect the expected Sekoia.io format.

Warning

Only the Sekoia.io forwarder is officially supported. Other options are documented for reference purposes but do not have official support.

Configure Aruba ClearPass syslog server

  1. Sign in to the ClearPass Policy Manager console.
  2. Select Administration > External servers > Syslog targets.
  3. Click Add.
  4. In the Add syslog target window that appears, specify the following details:
    • Host address: enter the syslog concentrator IP address.
    • Server port: enter the syslog concentrator port number.
    • Protocol: select UDP (you can also select TCP, depending on your syslog concentrator configuration).
  5. Click Save.

Configure syslog export filters

  1. Go to Administration > External servers > Syslog export filters.
  2. Click Add.
  3. In the Add Syslog Filters window that appears, specify the following in the General tab:
    • Name: enter the syslog export filter name based on the table in Export template items.
    • Export template: select the appropriate export template based on the table in Export template items.
    • Export event format type: select CEF.
    • Syslog servers: select the syslog concentrator IP address.
  4. In the Export template list, when you select the Session or Insight export templates, the Filter and columns tab is enabled. Complete the following steps:
    • Click the Filter and columns tab.
    • Data filter: make sure the default value All requests is selected.
    • Column selection: select the predefined field groups you want to get.
    • Click the Summary tab.
    • Click Save.
  5. In the Export template list, when you select the System events and Audit records export templates, the Filter and columns tab is not enabled. Proceed to the Summary tab and click Save.
  6. Repeat steps to add syslog export filters for all Session, Insight, Audit records and System events export templates based on the details from the table in Export template items.

Detection section

The following section provides information for those who wish to learn more about the detection capabilities enabled by collecting this intake. It includes details about the built-in rule catalog, event categories, and ECS fields extracted from raw events. This is essential for users aiming to create custom detection rules, perform hunting activities, or pivot in the events page.