When you configure Jenkins to send log data to USM Anywhere, you can use the Jenkins plugin to translate raw log data into normalized events for analysis. The table below provides some basic information for the plugin:
Before you configure the integration, you must have the IP address of the USM Anywhere Sensor.
To configure Jenkins to send log data to USM Anywhere
Configure the Jenkins Syslog Logger Plugin. See the Jenkins documentation for instructions.
- In the Syslog Server Hostname field, enter the IP address of the USM Anywhere Sensor.
In the Syslog Server Port field, select the port number depending on the transport protocol you want to use.
USM Anywhere listens for syslog at UDP port 514, TCP port 601, or TLS/TCP port 6514.
If using TLS with TCP, you need to download the certificate from USM Anywhere or upload your own certificate to USM Anywhere. See Configure Syslog on Your Data Sources for instructions.
- In the Syslog Logging Handler Filter Level field, select the logging level you want to use.
When assisting customers, AT&T Cybersecurity Technical Support noticed that the syslog message forwarded from Jenkins 2.177 appear in multiple lines. For example:
Jun 25 07:35:10 DEVICE-JENKINS jenkins: Jun 25, 2019 3:35:10 AM hudson.model.AsyncPeriodicWork$1 run
INFO: Started Fingerprint cleanup
However, the USM Anywhere Jenkins plugin only processes logs in the single-line format, causing the events to appear with no names. To work around this issue, you can use the following procedure to direct Jenkins to generate logs in single-line format instead.
To configure Jenkins to generate syslog in single-line format
Create a file named logging.properties and paste the following content inside:
java.util.logging.SimpleFormatter.format=[%1$tF %1$tT.%1$tL][%4$s][%2$s] %5$s %6$s%n
Add the file path to your Java arguments. For example:
Note: On most Linux distributions, you can find JAVA_ARGS in /etc/default/jenkins. You need root access to edit the file.
Your log should appear in single-line format, similar to this:
Jul 12 15:04:38 DEVICE-JENKINS jenkins: [2019-07-12 11:04:38.649][INFO][blah.model.Run execute] Test-Release #203 main build action completed: SUCCESS
The Jenkins plugin automatically processes all messages when the syslog tags contain jenkins.
Available Plugin Fields
The following plugin fields are important attributes extracted from the syslog message. The USM Anywhere reports use these fields, and you can also reference them when creating custom reports. In addition to reporting, the USM Anywhere correlation rules make use of these fields.