Security Compliance

Integrate Cisco ACS Syslog reports with SolarWinds SEM

This article describes how to integrate Cisco ACS Syslog Reports with SolarWinds SEM.

First published date

10/9/2018 8:39 PM

Last published date

10/9/2018 8:41 PM

Overview


This article provides steps to integrate Cisco ACS Syslog Reports with SolarWinds Security Event Manager (formerly Log & Event Manager).

You can integrate Cisco ACS with your SolarWinds SEM appliance to allow Cisco ACS logs to be stored on your SEM database and displayed as normalized Alerts in your SEM Console. 

Product section

Security Event Manager

Cause


 

Resolution

This involves two main steps:

I. Configure Logging on your Cisco ACS server

The first step in integrating Cisco ACS with SolarWinds SEM is to configure the recommended logging on the Cisco ACS server.

To configure syslog reporting on Cisco ACS version 4.1 or later:

  1. Log in to your CiscoSecure ACS web console.
  2. On the left navigation pane, click System Configuration.
  3. On the System Configuration page, click Logging.
  4. On the Logging Configuration page, click Configure in the Syslog column next to Failed Attempts.
  5. On the Syslog Failed Attempts File Configuration page, check Log to Syslog Failed Attempts report under Enable Logging.
  6. Under Select Columns to Log, move the appropriate attributes from the Attributes column to the Logged Attributes column by selecting them and clicking the ->button.

    The attributes that are necessary for SEM integration are listed in the tables below.

  7. Under Syslog Servers, enter the following information for your SEM Manager:
    • IP: SEM Manager IP Address.
    • Port: 514.
    • Max message length (Bytes): Leave this field blank.
  8. Click Submit.
  9. Repeat the steps above for each of these reports:
    • Passed Authentication
    • RADIUS Accounting
    • TACACS+ Accounting
    • TACACS+ Administration
    • VoIP Accounting

II. Configure the SEM manager

The next step in integrating Cisco ACS with SolarWinds SEM is to configure the Cisco Secure ACS 4.1 Syslog tool on your SEM manager.

Configure the Cisco Secure ACS 4.1 Syslog tool on your SEM manager

Flash console

  1. On SEM console menu bar, navigate to Manage > Appliances, and then log in to your SEM manager.
  2. Next to your SEM manager, click the gear icon, and select Connectors.
  3. In the connector Configuration window, enter ACS in the search box under Refine Results.
  4. Next to the Cisco Secure ACS 4.1 Syslog connector, click the gear icon, and then select New.
  5. Replace the Alias value with a custom Tool Alias, or accept the default.
  6. Leave the remaining values at their default unless your SEM implementation warrants otherwise. 
  7. Click Save.
  8. Next to the tool you just configured, click the gear icon, and then click Start. When the tool starts properly, its Status icon will turn green.
HTML5 console (versions 6.6 and newer)
  1. In the SEM Events Console, navigate to Nodes > Manager Connectors.
  2. In the search box, enter ACS.
  3. Select the Cisco Secure ACS 4.1 Syslog connector, and then click Add Connector.
  4. Enter a new name, or maintain the default, and then click Add.
  5. Under Configured connectors, select the connector, and then click Start.

You will now begin to see alerts from your Cisco ACS device in your SEM console. You can use the default All Alerts filter for this, or you can configure a custom filter to display all alerts with a ToolAlias value equal to the value you entered in Step 5.

Tables of ACS Report attributes by Report

The following tables list each of the report attributes needed for each ACS report that can be normalized by the Cisco ACS tool for SolarWinds SEM:

Failed Attempts Report Attributes

Message-TypeUser-NameGroup-NameCaller-IDAuthen-Failure-Code
Author-Failure-CodeAuthor-DataNAS-PortNAS-IP-Address
 


Passed Authentication Report Attributes

Message-TypeUser-NameGroup-NameCaller-IDNAS-Port
NAS-IP-AddressFilter InformationNetwork Access Profile NameShared RACDownloadable ACL
System-Posture-AssessmentApplication-Posture-AssessmentReasonEAP TypeEAP Type Name
 

RADIUS Accounting Report Attributes

User-NameGroup-NameCalling-Station-IdAcct-Status-TypeAcct-Session-Id
Acct-Session-TimeService-TypeFramed-ProtocolAcct-Input-OctetsAcct-Output-Octets
Acct-Input-PacketsAcct-Output-PacketsFramed-IP-AddressNAS-PortNAS-IP-Address
cisco-av-pairLogin-IP-HostLogin-Service  



TACACS+ Accounting Report Attributes
 
User-NameGroup-NameCaller-IdAcct-Flagselapsed_time
servicebytes_inbytes_outpaks_inpaks_out
task_idaddrNAS-PortnameNAS-IP-Addresscmd
 


TACACS+ Administration Report Attributes

User-NameGroup-Namecmdpriv-lvlservice
NAS-Portnametask_idNAS-IP-Addressreason 
 

VoIP Accounting Report Attributes

Call Leg Setup TimeGateway IdentifierConnection IdCall Leg DirectionCall Leg Type
Call Leg Connect TimeCall Leg Disconnect TimeCall Leg Disconnect CauseRemote Gateway IP Address

Disclaimer: Please note, any content posted herein is provided as a suggestion or recommendation to you for your internal use. This is not part of the SolarWinds software or documentation that you purchased from SolarWinds, and the information set forth herein may come from third parties. Your organization should internally review and assess to what extent, if any, such custom scripts or recommendations will be incorporated into your environment.  You elect to use third party content at your own risk, and you will be solely responsible for the incorporation of the same, if any.