ARP Guard
ArchivedThe ARPGuard application normalizes ARPGuard events. You can further customize the searches to perform in-depth analysis.
Release Details
Package Details
- Normalization Package
- LP_ARP Guard
- Compiled Normalizer
- ARPGuardCompiledNormalizer
Enhancement
A minor update has been done in the application’s normalizer for better signature handling.
Installation
Follow these steps to install the ARPGuard v5.0.1 application:
- Download the ARPGuard package from the Download section above.
- Add ARPGuard as the required device in LogPoint.
- Create a collection policy with the Syslog collector and appropriate processing policy.
- Assign the policy to the device.
Past Release
For LogPoint v6.0.0 to v6.6.6 ▾
Enhancement
A minor update has been done in the application’s normalizer for better signature handling.
Log Format
Expected Log Format
Syslog
Log Sample
<5>Aug 24 13:39:52 ARP-GUARD: New AAA event "start" message "Note: Device has been authenticated" client MAC "XX-XX-XX-XX-XX-XX" switch IP "1.1.1.1" switch port "X" RADIUS called station ID "XX-XX-XX-XX-XX-XX:AAAAAAAAA"
To export data to LogPoint, use Syslog collector on port 514 on the LogPoint server.
Support
If you have any questions or require assistance, create a support ticket.
Comments
Article is closed for comments.