Shibboleth
ArchivedThe Shibboleth application normalizes Shibboleth events and enables you to analyze the data using reports. You can further customize the searches to perform in-depth analysis.
Release Details
Package Details
- Report Packages
- LP_ShibbolethV2
- LP_ShibbolethV3
- LP_Shibboleth Identity Provider
- Compiled Normalizer
- ShibbolethV2CompiledNormalizer
Enhancement
Installation
Follow these steps to install the Shibboleth v5.0.1 application:
- Download the Shibboleth package from the Download section above.
- Add Shibboleth as the required device in LogPoint.
- Create a collection policy with the Syslog collector and appropriate processing policy.
- Assign the policy to the device.
Past Release
For LogPoint v6.0.0 to v6.6.6 ▾
Enhancement
Log Format
Expected Log Format
Syslog
Log Samples
<38>Apr 11 18:36:26 lp.dk [qtp1100439041-18] Shibboleth-Audit.SSO 20170411T163626Z|urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect|_b6be1a5696b56078697866ab58ab69a2|https://logpoint/|http://shibboleth.net/ns/profiles/saml2/sso/browser|https://logpoint|urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST|_8fa09988ea318874b6081a91766be4d2|username|urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport|uid,memberOf|AAdzZWNyZXQxeCGywE3Jjc7i4FlyGwUsnfenYMGjsy1+hFraT3oe7VBpoyZeGMA9hsV6axlw60L7pMi9l9DEdmT/Anq2uYjqUSGawsaXHn9S16NMTmiYjVj6FQIMHrjkSfU4ZOPUEjUcvotdO1w=|_dba21a2cd72ebda095809fa1b94bad9f|
16:45:18.260 - WARN [org.opensaml.common.binding.security.IssueInstantRule:108] - Message was expired: message issue time was '2017-03-29T10:12:37.000Z', message expired at: '2017-03-29T10:18:37.000Z', current time: '2017-11-02T16:45:18.260Z'
16:45:18.261 - WARN [edu.internet2.middleware.shibboleth.idp.profile.saml2.SSOProfileHandler:406] - Message did not meet security requirements
To export data to LogPoint, use Syslog collector on port 514 on the LogPoint server.
Support
If you have any questions or require assistance, create a support ticket.
Comments
Article is closed for comments.