OpenVPN
ArchivedThe OpenVPN application normalizes OpenVPN events and enables you to analyze OpenVPN data. You can further customize the searches to perform in-depth analysis.
Release Details
Package Details
- Normalization Package
- LP_OpenVPN
- Label Package
- LP_OpenVPN
Enhancement
A minor update has been done in the application’s normalizer for better signature handling.
Installation
Follow these steps to install the OpenVPN v5.0.0 plugin:
- Download the OpenVPN package from the Download section above.
- Add the required device in LogPoint.
- Create a collection policy with the Syslog collector and appropriate processing policy.
- Assign the policy to the device.
Important Notice
All the normalized field names used in this application are checked and aligned with the LogPoint taxonomy.
Log Format
Expected Log Format
- OpenVPN format
Log Sample
Tue Jan 17 07:51:24 2012 TCP/UDP: Incoming packet rejected from [AF_INET]1.1.1.1:1193[2], expected peer address: [AF_INET]2.2.2.2:1193 (allow this incoming source address/port by removing --remote or adding --float)
To export data to LogPoint use Syslog collector on port 514 on the LogPoint server.
Support
If you have any questions or require assistance, create a support ticket.
Comments
Article is closed for comments.