Security Compliance
Integrate Cisco ACS Syslog reports with SolarWinds SEM
This article describes how to integrate Cisco ACS Syslog Reports with SolarWinds SEM.
First published date
Last published date
Overview
This article provides steps to integrate Cisco ACS Syslog Reports with SolarWinds Security Event Manager (formerly Log & Event Manager).
You can integrate Cisco ACS with your SolarWinds SEM appliance to allow Cisco ACS logs to be stored on your SEM database and displayed as normalized Alerts in your SEM Console.
Product section
Cause
Resolution
This involves two main steps:
I. Configure Logging on your Cisco ACS server
The first step in integrating Cisco ACS with SolarWinds SEM is to configure the recommended logging on the Cisco ACS server.
To configure syslog reporting on Cisco ACS version 4.1 or later:
- Log in to your CiscoSecure ACS web console.
- On the left navigation pane, click System Configuration.
- On the System Configuration page, click Logging.
- On the Logging Configuration page, click Configure in the Syslog column next to Failed Attempts.
- On the Syslog Failed Attempts File Configuration page, check Log to Syslog Failed Attempts report under Enable Logging.
- Under Select Columns to Log, move the appropriate attributes from the Attributes column to the Logged Attributes column by selecting them and clicking the ->button.
The attributes that are necessary for SEM integration are listed in the tables below.
- Under Syslog Servers, enter the following information for your SEM Manager:
- IP: SEM Manager IP Address.
- Port: 514.
- Max message length (Bytes): Leave this field blank.
- Click Submit.
- Repeat the steps above for each of these reports:
- Passed Authentication
- RADIUS Accounting
- TACACS+ Accounting
- TACACS+ Administration
- VoIP Accounting
II. Configure the SEM manager
The next step in integrating Cisco ACS with SolarWinds SEM is to configure the Cisco Secure ACS 4.1 Syslog tool on your SEM manager.
Configure the Cisco Secure ACS 4.1 Syslog tool on your SEM manager
Flash console
- On SEM console menu bar, navigate to Manage > Appliances, and then log in to your SEM manager.
- Next to your SEM manager, click the gear icon, and select Connectors.
- In the connector Configuration window, enter ACS in the search box under Refine Results.
- Next to the Cisco Secure ACS 4.1 Syslog connector, click the gear icon, and then select New.
- Replace the Alias value with a custom Tool Alias, or accept the default.
- Leave the remaining values at their default unless your SEM implementation warrants otherwise.
- Click Save.
- Next to the tool you just configured, click the gear icon, and then click Start. When the tool starts properly, its Status icon will turn green.
- In the SEM Events Console, navigate to Nodes > Manager Connectors.
- In the search box, enter ACS.
- Select the Cisco Secure ACS 4.1 Syslog connector, and then click Add Connector.
- Enter a new name, or maintain the default, and then click Add.
- Under Configured connectors, select the connector, and then click Start.
You will now begin to see alerts from your Cisco ACS device in your SEM console. You can use the default All Alerts filter for this, or you can configure a custom filter to display all alerts with a ToolAlias value equal to the value you entered in Step 5.
Tables of ACS Report attributes by Report
The following tables list each of the report attributes needed for each ACS report that can be normalized by the Cisco ACS tool for SolarWinds SEM:
Failed Attempts Report Attributes
| Message-Type | User-Name | Group-Name | Caller-ID | Authen-Failure-Code |
| Author-Failure-Code | Author-Data | NAS-Port | NAS-IP-Address |
Passed Authentication Report Attributes
| Message-Type | User-Name | Group-Name | Caller-ID | NAS-Port |
| NAS-IP-Address | Filter Information | Network Access Profile Name | Shared RAC | Downloadable ACL |
| System-Posture-Assessment | Application-Posture-Assessment | Reason | EAP Type | EAP Type Name |
RADIUS Accounting Report Attributes
| User-Name | Group-Name | Calling-Station-Id | Acct-Status-Type | Acct-Session-Id |
| Acct-Session-Time | Service-Type | Framed-Protocol | Acct-Input-Octets | Acct-Output-Octets |
| Acct-Input-Packets | Acct-Output-Packets | Framed-IP-Address | NAS-Port | NAS-IP-Address |
| cisco-av-pair | Login-IP-Host | Login-Service |
TACACS+ Accounting Report Attributes
| User-Name | Group-Name | Caller-Id | Acct-Flags | elapsed_time |
| service | bytes_in | bytes_out | paks_in | paks_out |
| task_id | addr | NAS-Portname | NAS-IP-Address | cmd |
TACACS+ Administration Report Attributes
| User-Name | Group-Name | cmd | priv-lvl | service |
| NAS-Portname | task_id | NAS-IP-Address | reason |
VoIP Accounting Report Attributes
| Call Leg Setup Time | Gateway Identifier | Connection Id | Call Leg Direction | Call Leg Type |
| Call Leg Connect Time | Call Leg Disconnect Time | Call Leg Disconnect Cause | Remote Gateway IP Address |
Disclaimer: Please note, any content posted herein is provided as a suggestion or recommendation to you for your internal use. This is not part of the SolarWinds software or documentation that you purchased from SolarWinds, and the information set forth herein may come from third parties. Your organization should internally review and assess to what extent, if any, such custom scripts or recommendations will be incorporated into your environment. You elect to use third party content at your own risk, and you will be solely responsible for the incorporation of the same, if any.