Clavister CorePlus
ArchivedThe Clavister CorePlus application normalizes Clavister CorePlus events and enables you to analyze the data using pre-set dashboard views. You can further customize the dashboard and searches to perform in-depth analysis.
Release Details
Package Details
- Dashboard Package
- LP_Clavister CorePlus
- Label Package
- LP_Clavister CorePlus
- Compiled Normalizer
- ClavisterCorePlusCompiledNormalizer
Enhancement
Installation
Follow these steps to install the Clavister CorePlus v5.0.1 application:
- Download the Clavister CorePlus package from the Download section above.
- Add Clavister CorePlus as the required device in LogPoint.
- Create a collection policy with the Syslog collector and appropriate processing policy.
- Assign the policy to the device.
- Add the dashboard.
Past Release
For LogPoint v6.0.0 to v6.6.6 ▾
Enhancement
Log Format
Expected Log Format
Key=value pair separated by space
Log Samples
<134>[2012-04-04 13:43:27] EFW: IPSEC: prio=1 id=xxxxx rev=1 event=xauth_exchange_done statusmsg="Authentication failed"
<134>[2012-04-04 12:20:15] EFW: IPSEC: prio=1 id=xxxxxx rev=2 event=ipsec_event message=" Remote Proxy ID 1.1.1.1/24 any"
<132>[2012-04-04 13:39:55] EFW: IPSEC: prio=3 id=xxxxx rev=1 event=ipsec_sa_failed action=no_ipsec_sa statusmsg="No proposal chosen"
<132>[2012-04-04 13:36:13] EFW: IPSEC: prio=3 id=xxxxxx rev=2 event=ipsec_sa_selection_failed action=no_ipsec_sa_selected reason="Invalid proposal" int_severity=6
<133>[2012-04-04 13:33:35] EFW: IPSEC: prio=2 id=01802300 rev=1 event=rule_selection_failed info="Quick-Mode local ID mismatch" int_severity=6
<132>[2012-04-04 13:30:43] EFW: IPSEC: prio=3 id=01802715 rev=1 event=event_on_ike_sa side=Responder msg="failed" int_severity=6
To export data to LogPoint, use Syslog collector on port 514 on the LogPoint server.
Expected Log Format
Key=value pair separated by space
Log Samples
<134>[2012-04-04 13:43:27] EFW: IPSEC: prio=1 id=xxxxx rev=1 event=xauth_exchange_done statusmsg="Authentication failed"
<134>[2012-04-04 12:20:15] EFW: IPSEC: prio=1 id=xxxxxx rev=2 event=ipsec_event message=" Remote Proxy ID 1.1.1.1/24 any"
<132>[2012-04-04 13:39:55] EFW: IPSEC: prio=3 id=xxxxx rev=1 event=ipsec_sa_failed action=no_ipsec_sa statusmsg="No proposal chosen"
<132>[2012-04-04 13:36:13] EFW: IPSEC: prio=3 id=xxxxxx rev=2 event=ipsec_sa_selection_failed action=no_ipsec_sa_selected reason="Invalid proposal" int_severity=6
<133>[2012-04-04 13:33:35] EFW: IPSEC: prio=2 id=01802300 rev=1 event=rule_selection_failed info="Quick-Mode local ID mismatch" int_severity=6
<132>[2012-04-04 13:30:43] EFW: IPSEC: prio=3 id=01802715 rev=1 event=event_on_ike_sa side=Responder msg="failed" int_severity=6
To export data to LogPoint, use Syslog collector on port 514 on the LogPoint server.
Support
If you have any questions or require assistance, create a support ticket.
Comments
Article is closed for comments.