Artica Proxy
ArchivedThe Artica Proxy application normalizes Artica Proxy events and enables you to analyze Artica Proxy data. You can further customize the searches to perform an in-depth analysis.
Release Details
Package Details
- Normalization Package
- LP_Artica Proxy
Installation
Follow these steps to install the Artica Proxy v5.0.0 application:
- Download the Artica Proxy package from the Download section above.
- Add the required Artica Proxy server as a device in LogPoint.
- Create a collection policy with the Syslog collector and an appropriate processing policy.
- Assign the policy to the device.
Log Formats
Atrica Proxy
Expected Log Format
Common Log Format
Log Sample
remotehost rfc931 authuser [date] "request" status bytes
Expected Log Format
Key : Value
Log Sample
<182>May 18 16:14:38 CGLPROXY02 (squid-1): [Proxy-Connection: keep-alive\r\nUser-Agent: xxxxxxx/5.0 (Windows NT 6.3; Win64; x64) AppleWebKit/xxx.xx (KHTML, like xxxxx) Chrome/xx.x.xxxx.xx Safari/xxx.xx\r\nX-Forwarded-For: xxx.xx.xx.xxx\r\nHost: abc.com:xxx\r\n] [HTTP/1.1 407 Proxy Authentication Required\r\nServer: squid\r\nMime-Version: 1.0\r\nDate: Mon, 18 May 2020 14:14:38 GMT\r\nContent-Type: text/html;charset=utf-8\r\nContent-Length: XXXXX\r\nX-Squid-Error: ERR_CACHE_ACCESS_DENIED 0\r\n\r]
To export data to LogPoint, use the Syslog collector on port 514 of the LogPoint server.
Support
If you have any questions or require assistance, create a support ticket.
Comments
Article is closed for comments.