I have seen this in the past, and have an idication that it is from the Ingress Event Engine and related with a port-scan on your ClearPass appliance on the syslog port; which could be originating even from your ClearPass if you enabled the subnet scans. I have not further investigated yet myself.
If you don't use Ingress Event Engine, turn it off [in server manager]
Try to find where the scans on the syslog port may be originating from and try to disable it there; if it is your ClearPass subnet scan, disable it for the network where your ClearPass lives.
Open a case with your partner or Aruba Support (TAC) if you can't find the source.