HPE Aruba Clearpass (v1.0.36)

Aruba ClearPass Policy Manager provides role and device-based network access control for employees, contractors, and guests across any multivendor wired, wireless and VPN infrastructure.

Author
Cortex XSOAR
Support
xsoar
URL
https://www.paloaltonetworks.com/cortex
Categories
Network Security

Integrations (1)

Modeling rules (1)

Parsing rules (1)

README

HPE Aruba ClearPass

This pack includes Cortex XSIAM content.
<~XSIAM>

Collect Events from Product

You need to configure Aruba ClearPass to forward Syslog messages in CEF format.

Open your Aruba ClearPass UI and follow these instructions:

Adding Syslog Targets

  1. Navigate to Administration > External Servers > Syslog Targets.
  2. Click the Add link.
  3. Specify the server credentials at the prompt window.
  4. Click Save.

Adding a Syslog Export Filter

  1. Navigate to Administration > External Servers > Syslog Export Filters.
  2. From the Syslog Export Filters page, click Add.
    • Under Export Event Format Type, choose the Comma Event Format (CEF).
    • Under Syslog Servers, choose the relevant server config for XSIAM.
  3. Save your filter.

Use this content pack to help automate adding devices in the network to a block list in response to security events, such as a stolen or compromised device.

What does this pack do?

The integration in this pack enables you to: