I don't follow why you would point to the McAfee integration above?
To get close to the Access-Tracker information into your SIEM you 'll have to send multiple syslogs, I'd start with the below but use Insight, its tuned better.....
RADIUS:- Authentication, Failed Authentications, Accounting
If you need TACACS+, then TACACS+ Auth Nd Failed Auth
If you want other things, i.e. Guest stick with Insight and select the logs as needed.