Community Feedback

last person joined: 20 hours ago 

How is the community doing? Do you have any questions or feedback related for the Airheads Community team? This is the place to let us know.

Aruba Log Event ID's for Azure Sentinel Alerts

  • 1.  Aruba Log Event ID's for Azure Sentinel Alerts

    Posted Apr 29, 2020 05:18 AM

    Hi all,

    We have just setup azure sentinel. We are receiving syslogs from 3 aruba switches and 2 ap's. We need to create a query within Sentinel to give us an alert for security events. I found the query below for a cisco device so im planning on replacing the DeviceEventClassID's with event ID's from the aruba switches and ap's.

     

    Rule query

    let timeframe = 1h;

    CommonSecurityLog 

    | where TimeGenerated >= ago(timeframe)

    | where isempty(CommunicationDirection) 

    | where DeviceEventClassID in ("733101","733102","733103","733104","733105")

    | extend timestamp = TimeGenerated, IPCustomEntity = SourceIP, HostCustomEntity = DeviceName

     

    Has anyone experience linking Aruba devices with Sentinel or any SIEM system?

    Can anyone advise on event ID's we should be looking out for?

    We don't want to be getting alerts for every security event, just important ones we should be looking out for

     

    Thanks,

    Gary