Security

last person joined: 10 hours ago 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).

Sending session data via syslog

This thread has been viewed 3 times
  • 1.  Sending session data via syslog

    Posted Jun 27, 2018 07:22 AM

    Have configured the following syslog export filter. What else have I to do to get data appearing at the defined remote server ?

    General:
    Name:
    Test syslog export filter
    Description:
     
    Export Template:
    Session Logs
    Export Event Format Type:
    Standard
    Syslog Servers:
    nasaaa3.york.ac.uk
    ClearPass Servers:
    1. 144.32.230.6
    2. 144.32.128.85
    Filter and Columns:
    Option 1: For common use-cases, select Data Filter and Columns for export:
    Data Filter:
    [All Requests]
    Columns Selection:
    Common.Username
    Common.Host-MAC-Address
    Common.Roles
    Common.System-Posture-Token
    Common.Enforcement-Profiles
    Common.Request-Timestamp
    Common.Auth-Type
    Common.Connection-Status
    Common.Error-Code
    Common.Login-Status
    Common.Monitor-Mode
    Common.NAS-IP-Address
    Common.NAS-Port
    Common.Request-Id
    Common.Service
    Common.Session-Log-Timestamp
    RADIUS.Acct-NAS-IP-Address
    RADIUS.Acct-NAS-Port
    RADIUS.Acct-NAS-Port-Type
    RADIUS.Acct-Output-Octets
    RADIUS.Acct-Output-Pkts
    RADIUS.Acct-Service-Name
    RADIUS.Acct-Session-Id
    RADIUS.Acct-Session-Time
    RADIUS.Acct-Status-Type
    RADIUS.Acct-Termination-Cause
    RADIUS.Acct-Timestamp
    RADIUS.Acct-Username
    RADIUS.Auth-Method
    RADIUS.Auth-Source
    RADIUS.Session-Log-Timestamp