Cyberoam
ArchivedThe Cyberoam application normalizes Cyberoam events and enables you to analyze the data using pre-set dashboard views. You can further customize the dashboard and searches to perform in-depth analysis.
Release Details
Package Details
- Compiled Normalizer
- CyberoamCompiledNormalizer
- Dashboard Package
- LP_Cyberoam
- Normalization Package
- LP_Cyberoam
Enhancement
Installation
Follow these steps to install the Cyberoam v5.0.1 application:
- Download the Cyberoam package from the Download section above.
- Add Cyberoam as the required device in LogPoint.
- Create a collection policy with the Syslog collector and appropriate processing policy.
- Assign the policy to the device.
- Add the dashboard.
Past Release
For LogPoint v6.0.0 to v6.6.6 ▾
Enhancement
Log Format
Expected Log Format
Key = Value
Log Sample
<30>date=2019-08-07 time=13:25:27 timezone="IST" device_name="XXXX" device_id=XXXXX-VW717U log_id=011902605151 log_type="Firewall" log_component="IP Spoof" log_subtype="Denied" status="Deny" priority=Information duration=0 fw_rule_id=0 user_name="xxxxxxx" user_gp="my_group" iap=0 ips_policy_id=0 appfilter_policy_id=0 application="app name" in_interface="inf-0" out_interface="inf-1" src_mac=xxx src_ip=192.xxx.x.x src_country_code=NP dst_ip=192.xxx.x.x dst_country_code=US protocol="ICMP" icmp_type=0 icmp_code=0 sent_pkts=0 recv_pkts=0 sent_bytes=0 recv_bytes=0 tran_src_ip=xxx tran_src_port=0 tran_dst_ip=xxxxx tran_dst_port=0 srczonetype="src-zone" dstzonetype="dst-zone" dir_disp="Inbound" connid="xxxx" vconnid="yyyy
To export data to LogPoint, use Syslog collector on port 514 on the LogPoint server.
Support
If you have any questions or require assistance, create a support ticket.
Comments
Article is closed for comments.