PingFederate (Ping Identity) v1.0.0
PingFederate is a Ping Identity federation server that provides single sign-on (SSO), federated identity and API security for the enterprise.
- Author:
- Cortex XSOAR
- Support:
- xsoar
Modeling rules (1)
README
PingFederate (Ping Identity)
<~XSIAM>
Overview
PingFederate is the Ping Identity federation server that provides single sign-on (SSO), single logout (SLO), federated identity and API security using SAML, WS-Federation and OAuth/OpenID Connect.
What does this pack contain?
- Modeling Rules for the PingFederate audit log.
Supported Event Types
The modeling rule maps the PingFederate audit log events that are written in CEF format:
| Event | Description |
|---|---|
| AUTHN_ATTEMPT | Authentication attempt. |
| AUTHN_SESSION_CREATED | Authentication session created. |
| AUTHN_SESSION_USED | Existing authentication session used. |
| AUTHN_SESSIONS_DELETED | Authentication sessions deleted. |
| SSO | Single sign-on. |
| SLO | Single logout. |
| SRI_REVOKED | Session revocation index entry revoked. |
| OAuth | OAuth token request. |
Collect Events from PingFederate
To collect the PingFederate audit log, configure PingFederate to write the audit log in CEF format and forward it to Cortex XSIAM using a Broker VM.
Configure PingFederate to Write the Audit Log in CEF
- On the PingFederate server, open
<pf_install>/pingfederate/server/default/conf/log4j2.xml. - Enable the
SecurityAudit2CEFappender (the CEF audit log appender) and make sure it is referenced by theorg.sourceid.websso.profiles.**.**.SecurityAuditlogger. - Verify that the audit log pattern includes at least the
rt,msg,src,duid,dvchost,externalIdandcs1-cs6fields together with theircs1Label-cs6Labellabels. - Restart the PingFederate service.
For more information, see the Writing the audit log in CEF documentation.
Broker VM
To create or configure the Broker VM, see the Broker VM documentation.
Follow these steps to configure the Broker VM to receive the PingFederate audit log:
- Navigate to Settings > Configuration > Data Broker > Broker VMs.
- Go to the APPS column under the Brokers tab and add the Syslog Collector app for the relevant broker instance. If the app already exists, hover over it and click Configure.
- Click Add New to add a new syslog data source.
-
When configuring the new syslog data source, set the following parameters:
Parameter Value VendorEnter Ping Identity. ProductEnter PingFederate. ProtocolSelect the protocol used to forward the log (UDP, TCP or Secure TCP). FormatSelect CEF. PortEnter the port on which the broker listens for the PingFederate log.
</~XSIAM>