Logo
Sign in
  1. Logpoint Service Desk
  2. Products Hub
  3. Marketplace
default.png

Samba

Samba collects and normalizes Samba events and enables you to analyze its data.

Release Details
Version: 6.0.0
Release date: April 4th, 2025
Supported On: Logpoint v7.4.0 or later
Documentation: Samba Guide
SHA 256: 00305a902ba429095dfcef02f0a59812cf62804395c6e6d58933c3fc5d5d5707
Download

Package Details

Samba consists of the following components:

    1. Compiled Normalizer
      • SambaCompiledNormalizer

    2. Normalization Package
      • LP_Samba

    3. Log Source Template
      • Samba

 

Enhancement

Description Issue ID Reference ID
You can now use SambaCompiledNormalizer to normalize Samba authentication and audit logs. PLUG-15967 86887  

 

Past Releases

Samba v5.0.0

Fields

Details

Name

Samba

Version

5.0.0

Supported On

LogPoint v6.0.0 and later

Release Date

2020-05-14

Document Date

2020-05-14

Download

Samba_5.0.0.pak

SHA256

 4ccbe64bf953c84c7172df1c1a3c360c1cd9b3cafb86a459a19ceeaf2d948059

Package Detail

The application consist of the following component:

  1. Normalization Package
    • LP_Samba 

Enhancement

A minor update has been done in the application’s normalizer for better signature handling.

General Description

The Samba application normalizes Samba events and enables you to analyze Samba data. You can further customize the searches to perform in-depth analysis.

Installation 

Follow these steps to install the Samba v5.0.0 plugin:

  1. Download the Samba package from the Download section above.
  2. Add the required device in LogPoint.
  3. Create a collection policy with the Syslog collector and an appropriate processing policy. 
  4. Assign the policy to the device.

Supported Version

The supported versions of Samba with LogPoint in this configuration are:

  • Samba v3.x, v4.x

Log Format

Expected Log Format

  • Samba Format

Log Sample

[2002/07/21 13:23:25, 3] smbd/service.c:close_cnum(514) maya (1.16.1.6) closed connection to service IPC$

To export data to LogPoint use Syslog collector on port 514 on the LogPoint server.


Support

If you have any questions or require assistance, create a support ticket.

 

 

 

 

 

 

Comments

Article is closed for comments.

Follow

Related articles

  • SAML Authentication
  • CIFS Fetcher
  • Damerau-Levenshtein Process Plugin
  • Azure Log Analytics
  • Solar Winds Supply Chain Attack
Privacy policy    EULA    Terms of service   
Copyright © , Logpoint. All rights reserved.

Note: We use cookies that are essential for the smooth functioning of our website.