Generating Alerts for Security Events

HPE Aruba Networking Central supports configuring alerts for IDS Intrusion Detection System. IDS monitors a network or systems for malicious activity or policy violations and reports its findings to the management system deployed in the network. events.

For IDS events, you can generate alerts for infrastructure attacks and client attacks.

The following animation shows how to generate the alerts:

To generate alerts, complete the following steps:

  1. In the WebUI, use the filter to select Global.
  2. Under Analyze, click Alerts & Events.

    The Alerts & Events page is displayed.

  3. In the Alerts & Events page, click the Config icon.

    The Alert Severities & Notifications is displayed.

  4. Select Access Point tab to display the AP dashboard. HPE Aruba Networking Central supports three alert types for identifying interfering devices:
    • Rogue AP Detected
    • Infrastructure Attacks Detected
    • Client Attack Detected
  5. Select an alert and click + to enable the alert with default settings. To configure alert parameters, click the alert tile (anywhere within the rectangular box) and do the following:
    1. Severity—Set the severity. The available options are Critical, Major, Minor, and Warning.

      For a few alerts, you can configure a threshold value for one or more alert severities. To set the threshold value, select the alert and in the exceeds text box, enter the value. The alert triggers when one of the threshold values exceed the duration.

    2. Device Filter Options—(Optional) You can restrict the scope of an alert by setting one or more of the following parameters:
      • Group—Select a group to limit the alert to a specific group.
      • Label—Select a label to limit the alert to a specific label.
      • Sites—Select a site to limit the alert to a specific site.
    3. Notification Options
      • Email—Select the Email check box and enter an email address to receive notifications when an alert is generated. You can enter multiple email addresses, separate each value with a comma.
      • Streaming—Select the Streaming check box to receive the streaming notifications when an alert is generated.
      • Webhook—Select the Webhook check box and select the Webhook from the drop-down list. For more information, see Webhooks.
      • Syslog—Select the Syslog check box to receive the Syslog notifications when an alert is generated.
    4. Click Save.

For more information on how to configure Alerts, see Configuring Alerts.