Security

 View Only
  • 1.  Send Clearpass access tracker info to syslog

    Posted Apr 11, 2025 10:11 AM

    Hi there.  Our security people have asked that I send info to our security syslog server so they can track switch logins.  Our switches have TACACS set up on them so when we SSH to the switch it shows up in the live access tracker.  The problem is how to get that info to the syslog server!

    I've set up the server but when it comes to setting up the export filter I have no clue what option to use.  Searching for information on the settings brings back a million adverts for PRTG and some for Aruba Solution Exchange which is deceased!  I've tried selecting TACACS Request and TACACS logging in the filter options but it seems to send logs for absolute everything except the TACACS login tracking.  I tried whittling down the options but I either get nothing or absolutely tons of info except what I want.  Can anyone help?  I just want the access tracking info shown in Clearpass to be sent to the syslog server.



  • 2.  RE: Send Clearpass access tracker info to syslog

    Posted Apr 11, 2025 08:42 PM

    Perhaps you can configure "logging x.x.x.x" on your switches that will then send the events/logs to your SYSLOG server directly.



    ------------------------------
    If my post was useful accept solution and/or give kudos.
    Any opinions expressed here are solely my own and not necessarily that of HPE or Aruba.
    ------------------------------



  • 3.  RE: Send Clearpass access tracker info to syslog

    Posted Apr 14, 2025 04:14 AM

    The syslog service is part of a third party security service and access is controlled by IP.  I don't want to have to set up 200 new entries to send everything they have when all I want to send is the notifications our Clearpass server collects when someone logs on a switch.




  • 4.  RE: Send Clearpass access tracker info to syslog

    Posted Apr 21, 2025 10:33 AM

    I'm NO expert, but I believe that you can modify your "Syslog Export Filters" (Admin -> External Servers -> Syslog Export Filters) to send essentially whatever you want to the Syslog receiver.



    ------------------------------
    John MacDonald
    ----
    Just another geek trying to figure things out.
    ------------------------------



  • 5.  RE: Send Clearpass access tracker info to syslog

    Posted Apr 21, 2025 11:06 AM

    The issue is that I don't know what to filter.  Currently it's sending masses of information and I just want the login results.  Browsing through the ton of filters is not enlightening me as to which one it is I need to limit it too.  That's the info I need.  Which one sends the login result so our security app can record who logged into the switch?




  • 6.  RE: Send Clearpass access tracker info to syslog

    Posted Apr 21, 2025 11:46 AM

    Who logged into the Switch means you would need TACACS Logs to be sent to syslog.

    There is a thread related to this in Airheads community Clear Pass Syslog - TACACS Auth Login Failures

    Those filters will give you the requested values 



    ------------------------------
    Shpat | ACEP | ACMP | ACCP | ACDP
    Just an Aruba enthusiast and contributor by cases
    If you find my comment helpful, KUDOS are appreciated.
    ------------------------------