Network Management

last person joined: 22 hours ago 

Keep an informative eye on your network with HPE Aruba Networking network management solutions
Expand all | Collapse all

Configuring AirWave 8.2 RAPIDS to send syslogs events to a SIEM

This thread has been viewed 3 times
  • 1.  Configuring AirWave 8.2 RAPIDS to send syslogs events to a SIEM

    Posted Apr 11, 2016 02:51 PM

    In reveiwing the User Guide for AirWave 8.2 it specifically states "RAPIDS can be configured to alert administrators via email, SNMP traps, or syslog messages after a threat is identified" yet I can not seem to find where this is configurable. Within the system triggers email and snmp can be configured but not syslog.

     

    Anyone have any ideas?



  • 2.  RE: Configuring AirWave 8.2 RAPIDS to send syslogs events to a SIEM



  • 3.  RE: Configuring AirWave 8.2 RAPIDS to send syslogs events to a SIEM

    Posted Apr 12, 2016 11:29 AM

    This is for infrastructure event logs (device up/down) and audit logs (administrative changes) but I didn't think is also include RAPIDS events.



  • 4.  RE: Configuring AirWave 8.2 RAPIDS to send syslogs events to a SIEM

    Posted Sep 07, 2016 10:38 AM
    I'm looking for the same info as AirWave aggregates the RAPIDS events for a large deployment that I'm involved in.


  • 5.  RE: Configuring AirWave 8.2 RAPIDS to send syslogs events to a SIEM

    Posted Sep 28, 2016 08:02 PM

    Works mostly like in cjoseph's link:

    System > Triggers > Add

    Choose type - look for IDS Events section

     

    Here's a screenshot of my Rogue Device Detected alert - it sends me an email and a trap to syslog (which aggregates it in our SIEM)

    RAPIDS-trigger.png



  • 6.  RE: Configuring AirWave 8.2 RAPIDS to send syslogs events to a SIEM

    Posted Sep 29, 2016 07:59 AM

    Within your trigger setup you are having AirWave send Alert notifications to an NMS and you are selecting your NMS server but when you configure the NMS your only options are snmp there is no option for syslog. Am I missing something?

     

    "AMP can send SNMPv1, SNMPv2 traps or SNMPv3 in forms to NMS servers."



  • 7.  RE: Configuring AirWave 8.2 RAPIDS to send syslogs events to a SIEM

    Posted Sep 29, 2016 12:35 PM

    You're correct, I got confused.

    We send SNMP trap to NMS - a very good example of the wrong thing. Sorry.

    For syslog, we pipe all Airwave syslog to our central syslog server and pares the RAPIDS events there.



  • 8.  RE: Configuring AirWave 8.2 RAPIDS to send syslogs events to a SIEM

    Posted Sep 29, 2016 01:41 PM

    I fully understand that AirWave is capable to send data to a SIEM.

     

    My problem is there is no granularity in what we send to the SIEM. Having too much information is sometime worst than than having none.

     

    To aleviate the problem, I've add another SNMP server, which acts as a "proxy" where I filter out the unwanted stuff. This being said, I wish AirWave could make this on its own.