PortWise
ArchivedThe PortWise application normalizes PortWise events and enables you to analyze PortWise data using pre-set dashboard views. You can further customize the dashboard and searches to perform in-depth analysis.
Release Details
Package Details
- Dashboard Package
- LP_PortWise Authentication Server
- Normalization Packages
- LP_PortWise Authentication Server Generic
- LP_PortWise Authentication Server
Enhancement
Installation
Follow these steps to install the PortWise v5.0.0 plugin:
- Download the PortWise package from the Download section above.
- Add the required PortWise server as a device in LogPoint.
- Create a collection policy with the Syslog collector and appropriate processing policy.
- Assign the policy to the device.
- Add the dashboard.
Log Format
Expected Log Format
PortWise
Log Samples
<134>PortWise Policy Service 4.12.13: user: usnh7298qfb4: AUTHORIZATION ACCESS_CHALLENGED: Request URI: http://xyz.com/abc/ [ Resource URI:http://xyz.com/ ] CHALLENGE_MECHANISMS:[ 0 ]
<134>PortWise Policy Service 4.12.13: user1: znfgvzvdi5c: AUTHENTICATION NOT_AVAILABLE_AUTHENTICATION_SERVICE: AUTHENTICATION_MECHANISM:[ 2 ] MECHANISM_MESSAGE:[ Got no reply from any configured server ]
<134>PortWise Policy Service 4.12.13: user2: usnh7298qfb4: AUTHENTICATION USER_CHALLENGED: AUTHENTICATION_MECHANISM:[ 0 ] MECHANISM_MESSAGE:[ Password Invalid]
<134>PortWise Policy Service 4.12.13: user3: usnh7298qfb4: AUTHENTICATION USER_AUTHENTICATED: AUTHENTICATION_MECHANISM:[ 10 ] MECHANISM_MESSAGE:[ User 'hari' authenticated. ]
<134>PortWise Authentication Service 4.12.13: RADIUS client with address 1.1.1.1 makes an access request to Web Authentication
<134>PortWise Authentication Service 4.12.13: RADIUS client with address 1.1.1.3 makes an access request to Web Authentication
<132>PortWise Administration Service 4.12.13: Login attempt failed using xxxxxxxx
<134>PortWise Administration Service 4.12.13: xinger: 791FAxxxxxxxxxxxxxxxxxxxxxxxxxxxx: abc logged in successfully
<134>PortWise Administration Service 4.12.13: xinger: Updated a PortWise account xxxxxx of type account (key=jkik7nrocauxxxx)
To export data to LogPoint use Syslog collector on port 514 on the LogPoint server.
Support
If you have any questions or require assistance, create a support ticket.
Comments
Article is closed for comments.