Logo
Resources
Documentation Portal Ideas Portal Guardsix Academy License Portal
Resources
Documentation Portal Ideas Portal Guardsix Academy License Portal
Sign in
  1. Guardsix Servicedesk
  2. Products Hub
  3. Marketplace

Logpoint

Standard

Logpoint contains all the default Knowledge Base (KB) components and Logpoint plugins. Logpoint normalizes Logpoint audit events, Webserver Common Log Format events, and Kernel events and enables you to analyze the data using alerts, areports, and dashboards.

Release Details

Version: 5.2.2
Release date: 2022-07-15
SHA 256: 82e4edc93969a9f1aa9e2b08b3bebc8d04cd1559fe67cffa25da067415a77d48
Download

Enhancements

KB-17101
Added LP_Director Console normalization package to normalize Director Console events.
Added signatures in LP_Logpoint to normalize audit logs generated from Director Console .
Added labels in LP_Logpoint label package for audit logs generated from Director Console .

Installation

To install Logpoint:

  1. Download the .pak file from the Download section above.
  2. Go to Settings >> System Settings >> Applications.
  3. Click Import .
  4. Browse to the downloaded .pak file.
  5. Click Upload .

Past Releases

Changes in Logpoint v5.2.1 ▾
Version: 5.2.1

Enhancement

KB-1331542738, 49170, 50007, 54049
The label package has been updated to apply the Incident label for the event where Action = "Alert received . "
Changes in Logpoint v5.2.0 ▾
Version: 5.2.0

Enhancement

The application now includes the normalization package LP_Logpoint Audit , which supports Logpoint Web server audit logs that have been updated to handle a hostname.

Key Information

To export data to Logpoint, use the Syslog collector on
port 514 in the Logpoint server.

Log Formats

Logpoint Audit Log

Semicolon-separated

 2019-11-04_05:02:50 Logpoint INFO: plugin emailnotification; notification; updated; type=audit_log; source_address='::xxxx:1.1.1.1'; user='admin'

2021-03-22 07:04:41 Logpoint-132 INFO: LoggerPlugin; Alert received; type=alert_log; alert_name='Too mAny Logs'; incident_id='xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx'; alertrule_id='xxxxxxxxxxxxxxxxxxxxxxxxxxxx'; life_id='life_xxxxxxxxxxxxxxxxxxxxxxxxxxxx'; alert_id='xxxxxxxxxxxxxxxxxxxxxxxxxxxx'; status='unresolved'; risk_level='critical'; description=''; detection_timestamp='1616396681.9865444'; timerange_start='1616392800'; timerange_end='1616396400'; repos='["127.0.0.1:5504"]'; query='*'; tid=''

Web Server Common

Expected Log Format

"%h %l %u %t \"%r\" %>s %b"

Mar 6 08:28:02 apache: 1.1.1.1 - - [06/Mar/2012:08:28:02 +0100] "GET /cms/en/contact_us HTTP/1.0" 200 14922 "http://www.Logpoint.com/" "Mozilla/5.0 (Windows NT 5.1) AppleWebKit/534.30 (KHTML, like Gecko) Chrome/12.0.742.112 Safari/534.30"

Kernel Log

Key = value

13:06:46 ubuntu kernel: [4742881.976153] set_firewall; denied udp; IN=eth0 OUT= MAC=X:X:XX:XX:XX:XX:XX:XX:XX:XX SRC=X.X.X.X DST=XX.XX.X.XX LEN=XXX TOS=0x00 PREC=0x00 TTL=XX ID=XXXX PROTO=UDP SPT=XXXXXX DPT=XXX LEN=XX

Kernel Log

Key = value

13:06:46 ubuntu kernel: [4742881.976153] set_firewall; denied udp; IN=eth0 OUT= MAC=X:X:XX:XX:XX:XX:XX:XX:XX:XX SRC=X.X.X.X DST=XX.XX.X.XX LEN=XXX TOS=0x00 PREC=0x00 TTL=XX ID=XXXX PROTO=UDP SPT=XXXXXX DPT=XXX LEN=XX

Support

If you have any questions or require assistance, create a support ticket.

  • logpoint-logo.png (2 KB)

Comments

Article is closed for comments.

Follow

Related articles

  • Universal REST API Fetcher
  • ChatGPT Integration
  • AWSServices
  • FortiGate
  • ListProcessor
Consent Required To Proceed
By clicking “I Agree & Download”, you confirm that you are authorized to act on behalf of your organization and you give explicit consent for Guardsix to share your organization’s customer name and log source count with NXLog for the sole purposes of entitlement management, compliance verification, and support delivery related to the embedded NXLog technology in the Guardsix SIEM solution.

This data will not be used for sales or marketing and will not be shared with other third parties. You may withdraw your consent at any time by contacting Guardsix Support; withdrawal will not affect processing already performed.
Cancel I Agree & Download
Privacy policy    EULA    Terms of service   
Copyright © , Guardsix. All rights reserved.

Note: We use cookies that are essential for the smooth functioning of our website.