INSPIRA - Configuring Cisco Wireless LAN Controllers To QRadar SIEM - v1.0
INSPIRA - Configuring Cisco Wireless LAN Controllers To QRadar SIEM - v1.0
If you collect events from Cisco Wireless LAN Controllers, select the best collection method for your
configuration. The Cisco Wireless LAN Controller DSM for QRadar supports both syslog and SNMPv2
events. However, syslog provides all available Cisco Wireless LAN Controller events, whereas
SNMPv2 sends only a limited set of security events to QRadar.
Procedure
4. In the Syslog Server IP Address field, type the IP address of your QRadar Console.
5. Click Add.
The Information logging level allows the collection of all Cisco Wireless LAN Controller events above
the Debug logging level.
8. Click Apply.
What to do next
You are now ready to configure a syslog log source for Cisco Wireless LAN Controller.
When using the syslog protocol, there are specific parameters that you must use.
The following table describes the parameters that require specific values to collect syslog events
from Cisco Wireless LAN Controllers:
Configuring SNMPv2 for Cisco Wireless LAN Controller
SNMP event collection for Cisco Wireless LAN Controllers allows the capture of events for IBM
QRadar
Procedure
1. Log in to your Cisco Wireless LAN Controller interface.
You can use the one of the default communities that are created or create a new community.
4. Click New.
5. In the Community Name field, type the name of the community for your device.
The IP address and IP mask that you specify is the address from which your Cisco Wireless LAN
Controller accepts SNMP requests. You can treat these values as an access list for SNMP requests.
What to do next
To configure a trap receiver on your Cisco Wireless LAN Controller, take the following steps:
Procedure
1. Click the Management tab.
3. In the Trap Receiver Name field, type a name for your trap receiver.
The IP address you specify is the address to which your Cisco Wireless LAN Controller sends SNMP
messages. If you plan to configure this log source on an Event Collector, you want to specify the
Event Collector appliance IP address.
What to do next
The following table describes the parameters that require specific values to collect SNMPv2 events
from Cisco Wireless LAN Controllers: