Onapsis Security
ArchivedThe Onapsis Security application normalizes Onapsis Security events and enables you to analyze Onapsis Security data. You can further customize the searches to perform an in-depth analysis.
Release Details
Package Details
- Normalization Package
- LP_Onapsis Security Platform
Installation
Follow these steps to install the Onapsis Security v5.0.0 application:
- Download the Onapsis Security package from the Download section above.
- Add the required Onapsis Security server as a device in LogPoint.
- Create a collection policy with the Syslog collector and an appropriate processing policy.
- Assign the policy to the device.
Expected Log Source
Key = Value
Log Sample
<14>Oct 20 21:11:38 xxxxx 2017-10-20T19:11:38,060-0000 log_name=[satori.audit], user_id=6, user_name=xxxxx, request_id=xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxxxx, db_table=task_group, db_table_pk=4, action=Updated, change.owner.old="", change.owner.new="users:6", change.timestamp.old="", change.timestamp.new="2017-10-20T19:11:38,017917-0000", change.scan_job_id.old="", change.scan_job_id.new="3", change.job.old="", change.job.new="scan_job:3", change.owner_id.old="", change.owner_id.new="6"
To export data to LogPoint, use the Syslog collector on port 514 of the LogPoint server.
Support
If you have any questions or require assistance, create a support ticket.
Comments
Article is closed for comments.