Security Compliance

Configure Brocade Ironport series routers/switches in SEM

This article provides steps on configuring Brocade Ironport Series switches and routers in SEM.

First published date

10/30/2018 4:31 PM

Last published date

11/14/2022 12:52 PM

Overview

This article describes how to configure Brocade Ironport Series switches/routers in Security Event Manager (formerly Log & Event Manager).

Product section

Security Event Manager

Resolution

The following sections will guide you through configuring Brocade Ironport series routers/switches.

Configure syslog on Brocade switch/router 

Configure Brocade switch/router to send syslogs to SEM IP on UDP port 514 to a facility called local1. For more information, refer to the vendor documentation pages:

Determine if SEM is receiving data from the device 

  1. Connect to SEM using a virtual console or SSH client.
  2. Access the CMC prompt:
    • Virtual Console: Arrow down to Advanced Configuration, and then press Enter.
    • SSH Client: Log in using your CMC credentials.
  3. At the cmc> prompt, enter appliance.
  4. At the cmc::acm# prompt, enter checklogs.
  5. Enter an item number to select a log file to view.
  6. Check each log file that is not empty for evidence that the device is logging to the appliance, such as the device's product name, device name, or IP address.

Configure the Brocade router/switch connector in SEM 

In the HTML5 SEM Events Console:
  1. In the SEM Events Console, navigate to Nodes > Manager Connectors.
  2. In the search box, type Brocade.
  3. Select the Brocade connector you want to configure, and then click Add Connector.
  4. In the Name field, enter a new name, or keep the existing name.
  5. Ensure the Log file location is set to /var/log/local1.
  6. Click Add. The connector appears on the Manager Connectors tab under Configured connectors.
  7. Under Configured connectors, select your connector, and then click Start.

In the Flash-based SEM console:

  1. Log in to the SEM console.
  2. On the SEM menu bar, navigate to Manage > Appliances. 
  3. Next to the SEM manager, click the gear icon, and then select Connectors.
  4. In the Connector Configuration window, enter Brocade in the search box at the top of the Refine Results pane.

  5. Next to the Brocade Connector you are trying to configure, click the gear icon, and then select New. Ensure the Log file location is set to /var/log/local1 (shown below as an example).
  6. Click Save.

    Note: local1 is based on what you configured in the first section above in your Brocade Switch/Router.

  7. Next to the newly configured connector, click the gear icon, and then select Start.
Configure a filter to verify the data is coming in the the SEM Events Console Events viewer.
  1. In the SEM Events Console, click the Events tab.
  2. To create a filter at the root level, click the add  icon, and then select Add New Filter.
  3. Enter a descriptive name for your new filter (For example, Brocade Switch Router).
  4. In the Filter Values drag panel, expand Event Groups, and then select Any Alert.
  5. Under Any Alert fields, drag ToolAlias into the filter builder.
  6. Add your ToolAlias value, and then click Save. To find the ToolAlias value, select an applicable Brocade event log. In the Detail pane on the right, scroll down to ToolAlias.
You should start seeing events coming into the "Brocade Switch Router" Filter. If you don't see them, generate some events on a Brocade router/switch and go to section 2 above to verify and check back the filter. If you still do not see any events in the Monitor tab, it is likely there is unmatched data.

Configure a filter to verify the data is coming in to SEM Monitor tab 
  1. On the SEM console toolbar, click the Monitor tab.
  2. On the upper right of the Filters pane, click Create (big + sign on the left) > New Filter.

  3. Enter a name for the filter, such as Brocade switch and router.
  4. In the filters and groups list, click Event Groups > Any Alert, and then drag Tool Alias underneath the Conditions box to the right as shown below.

  5. On the lower right, click save. 

You should start seeing events coming into the "Brocade Switch Router" Filter. If you don't see them, generate some events on a Brocade router/switch and go to section 2 above to verify and check back the filter. If you still do not see any events in the Monitor tab, it is likely there is unmatched data.

 

Disclaimer: Please note, any content posted herein is provided as a suggestion or recommendation to you for your internal use. This is not part of the SolarWinds software or documentation that you purchased from SolarWinds, and the information set forth herein may come from third parties. Your organization should internally review and assess to what extent, if any, such custom scripts or recommendations will be incorporated into your environment.  You elect to use third party content at your own risk, and you will be solely responsible for the incorporation of the same, if any.