The issue is your ports are set to "trusted" meaning they are bypassing all firewall and visiblity. Can I make a suggestion? The below will retain your "plug and go" method but will use Aruba's firewall for device/client tracking on the wired ports.
1. Create a aaa profile. Assign NO MAC, 802.1x, or server group. Set the INITIAL ROLE to authenticated. This will still allow all traffic through.
2. Create your wired port profile as an "untrusted" port and then apply the aaa profile above.
Voila! You now have a ton more visibility (appRF also works here too!). You can do a simple search for the MAC and find out AP and port # very easily. This also gets reported to Airwave too.