Skip to content

HPE Aruba Networking Integration

Overview

HPE Aruba provides enterprise networking with wireless access points, switches, and SD-Branch solutions. KYRA MDR collects Aruba syslog data for monitoring wireless security and network access. Supports ArubaOS 8.x, AOS-CX, and Aruba Central.

Prerequisites

  • A KYRA MDR Collector installed and running
  • Aruba controller or switch with administrative access
  • Network connectivity from the device to the collector on port 514
  • ArubaOS 8.x or AOS-CX

Configuration

Configure syslog on ArubaOS controller:

configure terminal
logging <collector-ip>
logging level security debugging
logging level system informational
logging facility local7
write memory

For AOS-CX switches:

configure terminal
logging <collector-ip> tcp 514
logging facility local7
logging severity info
write memory

For Aruba Central, configure syslog under Organization > Webhooks > Syslog.

Collected Log Types

Log TypeDescriptionSecurity Use
SecurityAuthentication and authorization eventsAccess control monitoring
SystemController and switch eventsInfrastructure health
WirelessClient association and roaming eventsWireless monitoring
IDS/IPSWireless intrusion eventsRogue AP and attack detection
DHCPAddress assignment eventsClient tracking
UserUser login and access eventsIdentity monitoring

Troubleshooting

No wireless events: Ensure the security logging level is set to debugging.

Missing client events: Client events require the wireless logging category to be enabled on the controller.

Aruba Central: Aruba Central uses a webhook-based syslog export.

Contact kyra@seekerslab.com for support.