Airlock
ArchivedAirlock normalizes Airlock events and enables you to analyze Airlock data. You can further customize the searches and dashboard to perform in-depth analysis.
Release Details
Enhancement
A minor update has been done in the application’s normalizer for better signature handling.
Installation
Follow these steps to install the Airlock v5.0.0 plugin:
- Download the Airlock package from the Download section above.
- Add the required Airlock as a device in LogPoint.
- Create a collection policy with the Syslog collector and appropriate processing policy.
- Assign the policy to the device.
- Add the dashboard.
Log Format
Expected Log Format
Airlock WAF
Log Sample
Feb 1 09:17:16 airlock System: Feb 1 09:17:16 @Kxxxx---4xx--- Security sshd[xxxxx]: [authxxxx.info] Accepted password for xxxxx from xxx.xxx.x.xx port 1234 ssh2
Support
If you have any questions or require assistance, create a support ticket.
Comments
Article is closed for comments.