This sounds like an issue with the syslog server where when you add data from different areas (common, radius, ...) that it needs to do a SQL left outter join behind the scene that creates a problem and the syslog server sort of hangs up that filter.
If someone needs more info message me and I will look to find the details.
Original Message:
Sent: Mar 04, 2025 03:13 AM
From: hudaya1991
Subject: Clearpass stopped sending syslog to external syslog server
Dear aboehm,
noted, thanks for your confirmation
------------------------------
Regards,
Hudaya
ACCP, ATP, ACP-CA
Original Message:
Sent: Mar 04, 2025 03:05 AM
From: aboehm
Subject: Clearpass stopped sending syslog to external syslog server
Hello Hudaya,
yes, that's correct. I removed those and it started working again.
Cheers
Arthur
Original Message:
Sent: Feb 28, 2025 04:36 AM
From: hudaya1991
Subject: Clearpass stopped sending syslog to external syslog server
Dear @aboehm,
did you remove field common.roles and radius.acct-framed-ip-address to solve this issue ?
------------------------------
Regards,
Hudaya
ACCP, ATP, ACP-CA
Original Message:
Sent: Jul 14, 2023 05:16 AM
From: aboehm
Subject: Clearpass stopped sending syslog to external syslog server
Hi Herman,
i managed to get it running again. So I went through the audit viewer and double checked my changes. Somehow i accidentally reset the "selected columns" in the data filter to default values.
- Common.Username
- Common.Service
Common.Roles- Common.Host-MAC-Address
RADIUS.Acct-Framed-IP-Address- Common.NAS-IP-Address
- Common.Request-Timestamp
After adjusting the columns by removing those I don't need the logging started working again.
Cheers!
Original Message:
Sent: Jul 13, 2023 10:55 AM
From: Herman Robers
Subject: Clearpass stopped sending syslog to external syslog server
I checked TAC cases and found one where the syslog servers have been unreachable for some time and ClearPass for some reason did not pickup again. There modyfing anything with syslog, like you did solved the issue. So that probably is not it.
Also I found multiple cases where session logs were being sent, but the ClearPass appliance in question did not receive accounting data.
If you can't solve it with this, it may be best to get TAC involved to do further analysis.
------------------------------
Herman Robers
------------------------
If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.
In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
Original Message:
Sent: Jul 12, 2023 08:43 AM
From: aboehm
Subject: Clearpass stopped sending syslog to external syslog server
Hey guys,
i modified one of our Syslog Export Filters by adding a new syslog server and removing two Clearpass servers from the filter. Basically did some adjustments and saved them several times. At some point I noticed the existing logging stopped working after my adjustments. I did some troubleshooting and removed all of my changes, but the CPs won't log anymore to the syslog server based on the old export and data filters. I read some old threads and decided at some point to remove the config and re-create it, hoping for the best :) but still nothing coming out of the CP :(
TCPdump on the syslog server and also on the CP appliance confirm: nothing gets sent out on port 514 from the CP, except the CP system logs which are totally fine.
Does anyone have a hint or an idea? Currently ran out of ideas what could be the reason. Pls note: no changes on the network etc. have been done. Maybe somehow the service is stuck on the CP?
Cheers
Arthur