Hi Airheads,
I've attached a concise PDF documenting a sample integration of HPE Aruba ClearPass logs with Wazuh. The scope focuses on configuring Syslog message forwarding, decoding a sample RADIUS accounting record, and segregating events using custom Wazuh regex decoders to extract key fields useful for accounting, triage, and related operational needs.
I'd welcome any recommendations you think would add value, as well as questions or discussion points. Please feel free to reply here so we can continue the conversation.
Keep in mind that the decoders should work for other RADIUS, TACACS, WEBAUTH or INSIGHT logs.
Cheers,
Vigan
-------------------------------------------