Blue Coat
BlueCoat enables you to monitor and identify threats, blocked websites, website page views, and malicious activities in your organization using data from BlueCoat. The integration normalizes BlueCoat events and enables you to analyze the data using pre-set dashboard views. You can further customize the dashboard and searches to perform in-depth analysis.
Package Details
The application consists of the following components:
-
Dashboard Package
- LP_BlueCoat SG
-
Normalization Package
- LP_BlueCoat ProxySG
- LP_BlueCoat Audit
-
Compiled Normalizer
- BlueCoatnFMAINNormalizer
Enhancement
Description
|
Issue ID
|
Reference ID
|
---|---|---|
Added Syslog Collector based BlueCoat log source template, simplifying the log source configuration process. To learn more, go to Creating Log Source via a Template. |
KB-22631 |
- |
Installation
Follow these steps to install the BlueCoat v5.0.1 application:
- Download the BlueCoat package from the Download section above.
- Add the BlueCoat server as the required device in LogPoint.
- Create a log collection policy with the Syslog collector and appropriate processing policy.
- Assign the policy to the device.
- Add the dashboard.
Screenshots
Supported Log Formats
-
Format: bcreportermain_v1
The fields in HTTP main logs:
date time time-taken c-ip cs-username cs-auth-group x-exception-id sc-filter-result cs-categories cs(Referer) sc-status s-action cs-method rs(Content-Type) cs-uri-scheme cs-host cs-uri-port cs-uri-path cs-uri-query cs-uri-extension cs(User-Agent) s-ip sc-bytes cs-bytes x-virus-id x-bluecoat-application-name x-bluecoat-application-operation. -
Format: bcreportermain_plus
date time time-taken c-ip cs-username cs-auth-group x-exception-id sc-filter-result cs-categories cs(Referer) sc-status s-action cs-method rs(Content-Type) cs-uri-scheme cs-host cs-uri-port cs-uri-path cs-uri-query cs-uri-extension cs(User-Agent) s-ip sc-bytes cs-bytes x-virus-id x-bluecoat-application-name x-bluecoat-application-operation s-supplier-ip -
Format: bcreporterssl_v1
The fields in HTTPS main logs:
date time time-taken c-ip cs-username cs-auth-group x-exception-id sc-filter-result cs-categories sc-status s-action cs-method rs(Content-Type) cs-uri-scheme cs-host cs-uri-port cs-uri-extension cs(User-Agent) s-ip sc-bytes cs-bytes x-virus-id x-rs-certificate-observed-errors x-cs-ocsp-error x-rs-ocsp-error x-rs-connection-negotiated-cipher-strength x-rs-certificate-hostname x-rs-certificate-hostname-category -
Format: bcreporterssl_plus
date time time-taken c-ip cs-username cs-auth-group x-exception-id sc-filter-result cs-categories sc-status s-action cs-method rs(Content-Type) cs-uri-scheme cs-host cs-uri-port cs-uri-extension cs(User-Agent) s-ip sc-bytes cs-bytes x-virus-id x-rs-certificate-observed-errors x-cs-ocsp-error x-rs-ocsp-error x-rs-connection-negotiated-cipher-strength x-rs-certificate-hostname x-rs-certificate-hostname-category s-supplier-ip -
Format: Customized log format
date time time-taken c-ip cs-username cs-auth-group s-supplier-name s-supplier-ip s-supplier-country s-supplier-failures x-exception-id sc-filter-result cs-categories cs(Referer) sc-status s-action cs-method rs(Content-Type) cs-uri-scheme cs-host cs-uri-port cs-uri-path cs-uri-query cs-uri-extension cs(User-Agent) s-ip sc-bytes cs-bytes x-virus-id x-bluecoat-application-name x-bluecoat-application-operation cs-threat-risk x-bluecoat-transaction-uuid x-icap-reqmod-header(X-ICAP-Metadata) x-icap-respmod-header(X-ICAP-Metadata)
Supported Version
The supported version of BlueCoat with LogPoint in this configuration is:
- Access Logs for BlueCoat SG/BlueCoat SG Proxy - SGOS 6.5.2.1
To export data to LogPoint, use the Syslog collector on port 514 on the LogPoint server.
Package Details
The application consists of the following components:
-
Dashboard Package
- LP_BlueCoat SG
-
Normalization Package
- LP_BlueCoat ProxySG
- LP_BlueCoat Audit
-
Compiled Normalizer
- BlueCoatnFMAINNormalizer
Enhancement
A minor update has been done in the application’s normalizer for better signature handling.
Installation
Follow these steps to install the BlueCoat v5.0.1 application:
- Download the BlueCoat package from the Download section above.
- Add the BlueCoat server as the required device in LogPoint.
- Create a log collection policy with the Syslog collector and appropriate processing policy.
- Assign the policy to the device.
- Add the dashboard.
Screenshots
Supported Log Formats
-
Format: bcreportermain_v1
The fields in HTTP main logs:
date time time-taken c-ip cs-username cs-auth-group x-exception-id sc-filter-result cs-categories cs(Referer) sc-status s-action cs-method rs(Content-Type) cs-uri-scheme cs-host cs-uri-port cs-uri-path cs-uri-query cs-uri-extension cs(User-Agent) s-ip sc-bytes cs-bytes x-virus-id x-bluecoat-application-name x-bluecoat-application-operation. -
Format: bcreportermain_plus
date time time-taken c-ip cs-username cs-auth-group x-exception-id sc-filter-result cs-categories cs(Referer) sc-status s-action cs-method rs(Content-Type) cs-uri-scheme cs-host cs-uri-port cs-uri-path cs-uri-query cs-uri-extension cs(User-Agent) s-ip sc-bytes cs-bytes x-virus-id x-bluecoat-application-name x-bluecoat-application-operation s-supplier-ip -
Format: bcreporterssl_v1
The fields in HTTPS main logs:
date time time-taken c-ip cs-username cs-auth-group x-exception-id sc-filter-result cs-categories sc-status s-action cs-method rs(Content-Type) cs-uri-scheme cs-host cs-uri-port cs-uri-extension cs(User-Agent) s-ip sc-bytes cs-bytes x-virus-id x-rs-certificate-observed-errors x-cs-ocsp-error x-rs-ocsp-error x-rs-connection-negotiated-cipher-strength x-rs-certificate-hostname x-rs-certificate-hostname-category -
Format: bcreporterssl_plus
date time time-taken c-ip cs-username cs-auth-group x-exception-id sc-filter-result cs-categories sc-status s-action cs-method rs(Content-Type) cs-uri-scheme cs-host cs-uri-port cs-uri-extension cs(User-Agent) s-ip sc-bytes cs-bytes x-virus-id x-rs-certificate-observed-errors x-cs-ocsp-error x-rs-ocsp-error x-rs-connection-negotiated-cipher-strength x-rs-certificate-hostname x-rs-certificate-hostname-category s-supplier-ip -
Format: Customized log format
date time time-taken c-ip cs-username cs-auth-group s-supplier-name s-supplier-ip s-supplier-country s-supplier-failures x-exception-id sc-filter-result cs-categories cs(Referer) sc-status s-action cs-method rs(Content-Type) cs-uri-scheme cs-host cs-uri-port cs-uri-path cs-uri-query cs-uri-extension cs(User-Agent) s-ip sc-bytes cs-bytes x-virus-id x-bluecoat-application-name x-bluecoat-application-operation cs-threat-risk x-bluecoat-transaction-uuid x-icap-reqmod-header(X-ICAP-Metadata) x-icap-respmod-header(X-ICAP-Metadata)
Supported Version
The supported version of BlueCoat with LogPoint in this configuration is:
- Access Logs for BlueCoat SG/BlueCoat SG Proxy - SGOS 6.5.2.1
To export data to LogPoint, use the Syslog collector on port 514 on the LogPoint server.
Package Details
The application consists of the following components:
-
Dashboard Package
- LP_BlueCoat SG
-
Normalization Package
- LP_BlueCoat ProxySG
- LP_BlueCoat Audit
Enhancement
A minor update has been done in the application’s normalizer for better signature handling.
Installation
Follow these steps to install the BlueCoat v3.5.0 application:
- Download the BlueCoat package from the Download section above.
- Add the BlueCoat server as the required device in LogPoint.
- Create a log collection policy with the Syslog collector and appropriate processing policy.
- Assign the policy to the device.
- Add the dashboard.
Screenshots
Supported Log Formats
-
Format: bcreportermain_v1
The fields in HTTP main logs:
date time time-taken c-ip cs-username cs-auth-group x-exception-id sc-filter-result cs-categories cs(Referer) sc-status s-action cs-method rs(Content-Type) cs-uri-scheme cs-host cs-uri-port cs-uri-path cs-uri-query cs-uri-extension cs(User-Agent) s-ip sc-bytes cs-bytes x-virus-id x-bluecoat-application-name x-bluecoat-application-operation. -
Format: bcreportermain_plus
date time time-taken c-ip cs-username cs-auth-group x-exception-id sc-filter-result cs-categories cs(Referer) sc-status s-action cs-method rs(Content-Type) cs-uri-scheme cs-host cs-uri-port cs-uri-path cs-uri-query cs-uri-extension cs(User-Agent) s-ip sc-bytes cs-bytes x-virus-id x-bluecoat-application-name x-bluecoat-application-operation s-supplier-ip -
Format: bcreporterssl_v1
The fields in HTTPS main logs:
date time time-taken c-ip cs-username cs-auth-group x-exception-id sc-filter-result cs-categories sc-status s-action cs-method rs(Content-Type) cs-uri-scheme cs-host cs-uri-port cs-uri-extension cs(User-Agent) s-ip sc-bytes cs-bytes x-virus-id x-rs-certificate-observed-errors x-cs-ocsp-error x-rs-ocsp-error x-rs-connection-negotiated-cipher-strength x-rs-certificate-hostname x-rs-certificate-hostname-category -
Format: bcreporterssl_plus
date time time-taken c-ip cs-username cs-auth-group x-exception-id sc-filter-result cs-categories sc-status s-action cs-method rs(Content-Type) cs-uri-scheme cs-host cs-uri-port cs-uri-extension cs(User-Agent) s-ip sc-bytes cs-bytes x-virus-id x-rs-certificate-observed-errors x-cs-ocsp-error x-rs-ocsp-error x-rs-connection-negotiated-cipher-strength x-rs-certificate-hostname x-rs-certificate-hostname-category s-supplier-ip -
Format: Customized log format
date time time-taken c-ip cs-username cs-auth-group s-supplier-name s-supplier-ip s-supplier-country s-supplier-failures x-exception-id sc-filter-result cs-categories cs(Referer) sc-status s-action cs-method rs(Content-Type) cs-uri-scheme cs-host cs-uri-port cs-uri-path cs-uri-query cs-uri-extension cs(User-Agent) s-ip sc-bytes cs-bytes x-virus-id x-bluecoat-application-name x-bluecoat-application-operation cs-threat-risk x-bluecoat-transaction-uuid x-icap-reqmod-header(X-ICAP-Metadata) x-icap-respmod-header(X-ICAP-Metadata)
Supported Version
The supported version of BlueCoat with LogPoint in this configuration is:
- Access Logs for BlueCoat SG/BlueCoat SG Proxy - SGOS 6.5.2.1
To export data to LogPoint, use the Syslog collector on port 514 on the LogPoint server.
Support
If you have any queries or require assistance, create a support ticket.
Comments
Article is closed for comments.