Security

last person joined: 9 hours ago 

Enterprise security using ClearPass Policy Management, ClearPass Security Exchange, IntroSpect, VIA, 360 Security Exchange, Extensions and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Tracking admin changes to ClearPass

Jump to Best Answer
  • 1.  Tracking admin changes to ClearPass

    Posted Oct 17, 2017 06:55 PM

    I need to do some change auditing on our CPPM implementation and want to log when administrators make configuration changes in CPPM and in CPG.  Is it possible?  Running 6.6.5.93747.  



  • 2.  RE: Tracking admin changes to ClearPass
    Best Answer

    Posted Oct 17, 2017 06:58 PM
    You should see these changes in the audit log.


  • 3.  RE: Tracking admin changes to ClearPass

    Posted Oct 18, 2017 02:14 PM

    Thanks much for the reply cappalli.  Unfortunately not to the extent that I am looking for.  The genesis of looking into this is that we had someone give users more controlls in the user portal than they should have had, at an unknown point in time. 

     

    Since then, there have been multiple config changes in Guest Manager, yet not all of those config change instances are showing up in the Audit log (CPPM > Monitoring > Audit Viewer) and what is there just says that a change was made to Guest Manager, not what changed.  We are really looking to get a lot more granualrity.  The Manual for 6.6 CPPM is frustratingly light on logging configuration.  



  • 4.  RE: Tracking admin changes to ClearPass

    Posted Oct 18, 2017 10:28 PM

    In a future release we will be adding the ability to send the contents of the CPG Application log to an external syslog server, hopefully that will help.



  • 5.  RE: Tracking admin changes to ClearPass

    Posted Oct 25, 2017 03:23 PM

    Thanks much dannyjump.  Not ideal, but we will eagerly await the new functionality, which I would hope is forthcoming fairly soon.  Change auditing is becoming more critical for us, so getting granularity in the logs will be a welcomed feature.  

     

    -Skeeter



  • 6.  RE: Tracking admin changes to ClearPass

    Posted Oct 25, 2017 09:08 PM

    It won't be in this quarter. 



  • 7.  RE: Tracking admin changes to ClearPass

    Posted Nov 12, 2018 06:48 PM

    Any news on getting cpg_application_log exporting to syslog?

    Seems like this is going to be a challenge with the current (in 6.6 anyway) 1024 byte syslog message limit or will that be adjusted upward?



  • 8.  RE: Tracking admin changes to ClearPass

    Posted Nov 12, 2018 06:54 PM
    This was added in ClearPass 6.7.0