Skip to main content

How to integrate your HPE Aruba Switch with Defense.com

This guide will run you through how to get your Aruba Switch logging to Defense.com's SIEM platform.

Alan Butcher avatar
Written by Alan Butcher
Updated over a week ago

This integration is available on our Advanced and Enterprise packages.

Before you get started

Before beginning the integration, you will need to deploy a log collector within the same network as your firewall.

To start the collector deployment process, please contact our Technical Support team, who'll provide you with a deployment pack that includes all the software and scripts needed to configure this.

If you already have a log collector deployed, please follow the steps outlined below.

Configuring syslog

  1. Open a web browser and navigate to the switch's management IP address.

  2. Log in using your credentials.

  3. Go to System > Logging, you may also see a section for Syslog

  4. Locate the logging servers table and click the + add icon to add a new server.

  5. Enter the private IP address of your log collector

  6. Specify the UDP port 5514 (not the default of 514)

  7. Select the appropriate severity level for the logs you want to send. This could be a specific level like Warning or Error, or a broader level like Informational. If needed, configure the VRF (Virtual Routing and Forwarding) context for the logging server

  8. Click Apply, then Save

Confirming log flow

Once the above steps are complete, your device will now ship logs to our SIEM platform via your collector. You can confirm logs are successfully reaching our SIEM by either.

  1. Navigating to the Log Search feature in Defense.com by browsing to SIEM > Log Search and then filtering the logs by type:"syslog".

  2. Reaching out to our Technical Support team, who'll be able to check and confirm this for you.

And that's it! You've successfully integrated your Aruba Switch πŸŽ‰

Did this answer your question?