HPE Aruba Networking Integration
Overview
HPE Aruba provides enterprise networking with wireless access points, switches, and SD-Branch solutions. KYRA MDR collects Aruba syslog data for monitoring wireless security and network access. Supports ArubaOS 8.x, AOS-CX, and Aruba Central.
Prerequisites
- A KYRA MDR Collector installed and running
- Aruba controller or switch with administrative access
- Network connectivity from the device to the collector on port 514
- ArubaOS 8.x or AOS-CX
Configuration
Configure syslog on ArubaOS controller:
configure terminallogging <collector-ip>logging level security debugginglogging level system informationallogging facility local7write memoryFor AOS-CX switches:
configure terminallogging <collector-ip> tcp 514logging facility local7logging severity infowrite memoryFor Aruba Central, configure syslog under Organization > Webhooks > Syslog.
Collected Log Types
| Log Type | Description | Security Use |
|---|---|---|
| Security | Authentication and authorization events | Access control monitoring |
| System | Controller and switch events | Infrastructure health |
| Wireless | Client association and roaming events | Wireless monitoring |
| IDS/IPS | Wireless intrusion events | Rogue AP and attack detection |
| DHCP | Address assignment events | Client tracking |
| User | User login and access events | Identity monitoring |
Troubleshooting
No wireless events: Ensure the security logging level is set to debugging.
Missing client events: Client events require the wireless logging category to be enabled on the controller.
Aruba Central: Aruba Central uses a webhook-based syslog export.
Contact kyra@seekerslab.com for support.