For the complete documentation index, see llms.txt. This page is also available as Markdown.

HPE Aruba Wireless

Integration Guide for HPE Aruba Wireless Controller with BluSapphire SIEM

Prerequisites

Confirm the following before starting configuration:

Requirement

Detail

Aruba Controller Admin access

Administrator login to the Aruba Controller (GUI or CLI access).

Network access

UDP port open from Aruba Controller to BluSapphire DataStreamer

Information needed

BluSapphire DataStreamer’s static private IP and UDP port number (to be shared by BluSapphire team)

Configuration Steps

Follow the steps below to add and configure the remote syslog server on the Aruba Controller.

  1. Configure using UI, please follow the below procedure for the respective old & new UIs.

Old UI

  • In the Instant main window, click the System link.

  • Click Show advanced options to display the advanced options.

  • Click the Monitoring tab. The Monitoring tab details are displayed.

New UI

  • Go to Configuration > System.

  • Click Show advanced options.

  • Expand Monitoring tab. The Monitoring tab details are displayed.

  1. In the Syslog server text box which is in the Servers section, enter the Forwarder IP address of the server to which you want to send system logs.

  1. Select the required values to configure syslog facility levels. Syslog Facility is an information field associated with a syslog message. It is an application or operating system component that generates a log message. The following seven facilities are supported by Syslog:

AP-Debug — Detailed log about the AP device.

Network— Log about change of network, for example, when a new IAP is added to a network.

Security — Log about network security, for example, when a client connects using wrong password.

System— Log about configuration and system status.

User— Important logs about client.

User-Debug — Detailed log about client.

Wireless— Log about radio.

  1. Click OK.

Last updated