Juniper Networks Steel-Belted Radius
What is Discovered and Monitored
Protocol |
Information discovered |
Metrics collected |
Used for |
---|---|---|---|
SNMP |
Application type |
Process level CPU utilization, Memory utilization |
Performance Monitoring |
WMI |
Application type, service mappings |
Process level metrics: uptime, CPU Utilization, Memory utilization, Read I/O, Write I/O |
Performance Monitoring |
Syslog |
Application type |
Successful and Failed Authentications, Successful and Failed administrative logons, RADIUS accounting logs |
Security Monitoring and compliance |
Event Types
In ADMIN > Device Support > Event Types, search for "Juniper-Steelbelt" to see the event types associated with this device.
Configuration
SNMP
FortiSIEM uses SNMP to discover and monitor this device. Make sure SNMP is enabled for the device as directed in its product documentation. For more information, refer to sections "Discovery Settings" and "Setting Credentials" in the User Guide.
Syslog
For Windows Agent, take the following steps:
-
Login to FortiSIEM GUI.
-
Navigate to Admin > Setup, and click the Windows Agent tab.
-
Under Windows Agent Monitor Templates, click New to create a new template, or click an existing template and click Edit.
-
If creating a new template, on the Generic tab, in the Name field, enter a name for the template.
-
Click the User Log tab, and click New.
-
In the Full File Name field, enter the full file name (including path) to be monitored.
-
In the Log Prefix field, enter a log prefix that needs to be added to the log.
-
Click Save.
-
-
Click Save.
-
Under Host To Template Associations, click New to create an Host To Template Associations, or select an existing one and click Edit.
-
If creating a new Host To Template Associations, in the Name field, enter a name for this Host To Template Associations.
-
From the Host drop-down list, select the host(s).
-
At Template, attach the template to one or more server hosts by selecting its checkbox, then click Save.
-
Under Host to Template Associations, click Apply.
The logs will have a prefix set by Log Prefix that can be used to write a Parser for these files.
For details, see Configuring Windows Agent.
For Linux Agent, take the following steps:
-
Login to FortiSIEM GUI.
-
Navigate to Admin > Setup, and click the Linux Agent tab.
-
Under Linux Agent Monitor Templates, click New to create a new template, or click an existing template and click Edit.
-
If creating a new template, on the Generic tab, in the Name field, enter a name for the template.
-
Click the Log File tab, and click New.
-
In the Full File Name field, enter the full file name (including path) to be monitored.
-
In the Log Prefix field, enter a log prefix that needs to be added to the log.
-
Click Save.
-
-
Click Save.
-
Under Host To Template Associations, click New to create an Host To Template Associations, or select an existing one and click Edit.
-
If creating a new Host To Template Associations, in the Name field, enter a name for this Host To Template Associations.
-
From the Host drop-down list, select the host(s).
-
At Template, attach the template to one or more server hosts by selecting its checkbox, then click Save.
-
Under Host to Template Associations, click Apply.
The logs will have a prefix set by Log Prefix that can be used to write a Parser for these files.
For details, see Configuring Linux Agent.