Logo
Sign in
  1. Logpoint Service Desk
  2. Products Hub
  3. Marketplace
app-115003783485.png

Squid

The Squid application normalizes Squid events and enables you to analyze the data using pre-set dashboard views. You can further customize the dashboard and searches to perform in-depth analysis.

For Logpoint version:

6.7.0 or later 6.0.0 to 6.6.6
Release Details
Version:5.0.1
Release date:2020-05-14
Document date:2020-05-14
SHA 256: 9c91dba75dcb704b95f179434bf57c17fe752826057c6e8362b44427dd1f06c8
Download

Package Details

The application consist of the following components:

  1. Dashboard Packages
    • LP_Squid 
    • LP_Squid General 
  2. Label Package
    • LP_Squid 
  3. Normalization Packages
    • LP_Squid dynamic 
    • LP_Squid 

Enhancement

A minor update has been done in the application’s normalizer for better signature handling.

Installation

Follow these steps to install the Squid v5.0.1 application:

  1. Download the Squid package from the Download section above.
  2. Add Squid as the required device in LogPoint.
  3. Create a collection policy with the Syslog collector and appropriate processing policy. 
  4. Assign the policy to the device.
  5. Add the dashboard.

Screenshots

squid.pngsquid1.png

 

Supported Devices

The supported devices of Squid with LogPoint in this configuration are:

  • Squid Cache v2.6 and later

Squid Configuration File

logformat logpoint  source_address="%>a" source_host="%>A" source_hardware_address="%>eui" destination_address="%<a" destination_host="%<A" destination_port="%<p" log_ts="%ts" dns_wait="%dt" transaction_time="%tr" user="%un" request_method="%>rm" url="%ru" domain="%<A" datasize="%st" sent_datasize="%>st" received_datasize="%<st" status_code="%>Hs" adapt_datasize="%<st" total_time="%<tt" proxy_status="%Ss"

Log Sample

<182>Sep 22 15:45:41 prx006 squid[21198]: 1442951141.082 28 10.162.10.206 TCP_MISS/301 677 GET http://www.xyz.com/milestone/images/xyz_milestone_letter_header.jpg clhcrco DEFAULT_PARENT/proxy147.xyz.com text/html <166>Mar 12 19:19:29 proxyA squid[1563]: 1363112368.695 64027 1.1.1.0 TCP_MISS/200 15785 CONNECT xyz.com:443 - DIRECT/1.1.1.1 adfdf

Use the following methods to send data to LogPoint:

  1. Send the data to the local Syslog facility of the server:

access_log syslog:local1.info logpoint

2. send the events directly to LogPoint:

access_log udp://172.16.48.130:514 logpoint

Release Details
Version:3.7.0
Release date:2020-05-14
Document date:2020-05-14
SHA 256: e1cca73227ff63259cde12203b1f6ee3ebb770bb480508c2965a1365203de788
Download

Package Details

The application consist of the following components:

  1. Dashboard Packages
    • LP_Squid 
    • LP_Squid General 
  2. Label Package
    • LP_Squid 
  3. Normalization Packages
    • LP_Squid dynamic 
    • LP_Squid 

Enhancement

A minor update has been done in the application’s normalizer for better signature handling.

Installation 

Follow these steps to install the Squid v3.7.0 application:

  1. Download the Squid package from the Download section above.
  2. Add Squid as the required device in LogPoint.
  3. Create a collection policy with the Syslog collector and appropriate processing policy. 
  4. Assign the policy to the device.
  5. Add the dashboard.

Screenshots

squid.pngsquid1.png

Supported Devices

The supported devices of Squid with LogPoint in this configuration are:

  • Squid Cache v2.6 and later

Squid Configuration File

logformat logpoint  source_address="%>a" source_host="%>A" source_hardware_address="%>eui" destination_address="%<a" destination_host="%<A" destination_port="%<p" log_ts="%ts" dns_wait="%dt" transaction_time="%tr" user="%un" request_method="%>rm" url="%ru" domain="%<A" datasize="%st" sent_datasize="%>st" received_datasize="%<st" status_code="%>Hs" adapt_datasize="%<st" total_time="%<tt" proxy_status="%Ss"

Log Sample

<182>Sep 22 15:45:41 prx006 squid[21198]: 1442951141.082 28 10.162.10.206 TCP_MISS/301 677 GET http://www.xyz.com/milestone/images/xyz_milestone_letter_header.jpg clhcrco DEFAULT_PARENT/proxy147.xyz.com text/html <166>Mar 12 19:19:29 proxyA squid[1563]: 1363112368.695 64027 1.1.1.0 TCP_MISS/200 15785 CONNECT xyz.com:443 - DIRECT/1.1.1.1 adfdf

Use the following methods to send data to LogPoint:

  1. Send the data to the local Syslog facility of the server:

access_log syslog:local1.info logpoint

2. send the events directly to LogPoint:

access_log udp://172.16.48.130:514 logpoint


Support

If you have any queries or require assistance, please feel free to contact our support team: 

Email: servicedesk@logpoint.com
Phone: +45 7060 6100

Best regards,
untitled.svg

Comments

Article is closed for comments.

Follow

Related articles

  • Stix/Taxii
  • NXLog Enterprise
  • Cisco
  • SpotCheck Process Plugin
  • Artica Proxy
Privacy policy    EULA    Terms of service   
Copyright © , Logpoint. All rights reserved.

Note: We use cookies that are essential for the smooth functioning of our website.