Adding an SIEM Server

To add an SIEM Security Incident and Event Management (SIEM) is a server where Aruba IDPS sends the threat data to perform advanced analysis and generate reports. SIEM provides a holistic picture of the security posture by aggregating and correlating data from disparate sources in the network. for IDPS Intrusion Detection and Prevention System (IDPS) monitors, detects, and prevents threats in the inbound and outbound traffic. Aruba IDPS provides an extra layer of protection that actively analyzes the network and takes actions on the traffic flows based on the defined rules. It inspects data packets, and if any threat is identified, acts real-time to prevent it., complete the following steps:

  1. In the WebUI, set the filter to Global.
    The dashboard context for all devices is displayed.
  2. Under Manage, click Security > Gateway IDS/IPS.
  3. Click the Config icon to open the Gateway IDS/IPS configuration page.
  4. Click the SIEM tab.
  5. Click + in the Servers table.
  6. In the Add SIEM Server window, enter the following details:
  7. Click Test Connection to verify if the connection to the SIEM server is working.
  8. Click Add.

For the threat data to be reported to this server, ensure that you have enabled reporting to SIEM server.

Supported URL Formats

The following are the URL formats that are accepted for the IDPS SIEM server configuration.

Table 1: Supported SIEM URL formats

Splunk URL Example

Acceptable URL Format

https://prd-p-op170.splunkcloud.com

https://prd-p-op170.splunkcloud.com:8088

https://http-inputs-abc.splunkcloud.com:443/services/collector/event

https://http-inputs-abc.splunkcloud.com:443