Arbor Networks Pravail
The JSA DSM for Arbor Networks Pravail receives event logs from your Arbor Networks Pravail servers.
The following table identifies the specifications for the Arbor Networks Pravail DSM:
Specification |
Value |
---|---|
Manufacturer |
Arbor Networks |
DSM |
Arbor Networks Pravail |
RPM file name |
DSM-ArborNetworksPravail-build_number.noarch.rpm |
Protocol |
Syslog |
Recorded events |
All relevant events |
Automatically discovered? |
Yes |
Includes identity? |
No |
Includes custom properties? |
No |
More information |
To send Arbor Networks Pravail events to JSA, complete the following steps:
If automatic updates are not enabled, download and install the most recent version of the Arbor Networks Pravail RPM from the https://support.juniper.net/support/downloads/ onto your JSA console.
Configure each Arbor Networks Pravail system to send events to JSA.
If JSA does not automatically discover the Arbor Pravail system, create a log source on the JSA console. Configure the required parameters, and use the following table for the Arbor Pravail specific parameters:
Table 2: Arbor Pravail Parameters Parameter
Value
Log Source Type
Arbor Networks Pravail
Protocol Configuration
Syslog
Configuring Your Arbor Networks Pravail System to Send Events to JSA
To collect all audit logs and system events from Arbor Networks Pravail, you must add a destination that specifies JSA as the syslog server.
Log in to your Arbor Networks Pravail server.
Click Settings & Reports.
Click Administration >Notifications.
On the Configure Notifications page, click Add Destinations.
Select Syslog.
Configure the following parameters:
Table 3: Syslog Parameters Parameter
Description
Host
The IP address of the JSA console
Port
514
Severity
Info
Alert Types
The alert types that you want to send to the JSA console
Click Save.
Arbor Networks Pravail Sample Event Message
Use this sample event message to verify a successful integration with JSA.
Due to formatting issues, paste the message format into a text editor and then remove any carriage return or line feed characters.
Arbor Networks Pravail sample message when you use the Syslog protocol
The following sample event message shows that a malformed SIP traffic is blocked.
<25>May 15 17:17:31 arbornetworks.pravail.test arbor-networks-aps: Blocked Host: Blocked host 192.168.124.175 at 05:16 by Block Malformed SIP Traffic using UDP/5060 (SIP) destination 192.168.161.35 source port 5060,URL: https://arbornetworks.pravail.test/summary/
JSA field name |
Highlighted values in the event payload |
---|---|
Event ID |
Block Malformed SIP Traffic |
Event Category |
Blocked Host |
Source IP |
192.168.124.175 |
Source Port |
5060 |
Destination IP |
192.168.161.35 |
Destination Port |
5060 |
Device Time |
May 15 17:17:31 |