Aruba ClearPass
Connect Aruba ClearPass to Radiant Security to forward authentication, authorization, and accounting logs for AI triage.
Aruba ClearPass is a network access control (NAC) platform that authenticates and authorizes users and devices joining wired, wireless, and VPN networks, and enforces policy to contain unmanaged or compromised endpoints. Connecting Aruba ClearPass forwards authentication, authorization, accounting, and session logs to Radiant Security via syslog through the Radiant Agent. Radiant uses ClearPass logs to enrich identity and network-access artifacts during triage, giving analysts visibility into who connected, from what device, and whether the access decision succeeded or failed.
Prerequisites
Add the data connector in Radiant Security
Sign in to Radiant Security.
From the navigation menu, select Settings > Data Connectors and click + Add Connector.
Search for and select Radiant Agent, then click Data Feeds.
Under Select your data feeds, select Aruba ClearPass (syslog), then click Credentials.
Under Credential Name, enter an identifiable name for the Radiant Agent integration (e.g.,
Aruba ClearPass Credentials), or select an existing Radiant Agent credential from the drop-down menu.Click Add Connector.
Add a syslog target on Aruba ClearPass
Before starting, confirm the IP address of the Radiant Agent and the port configured to receive Aruba ClearPass data. If you do not know the port, contact your Customer Success representative.
Sign in to the Aruba ClearPass console.
Navigate to Administration > External Servers > Syslog Targets.

Click Add.
Enter the following parameters:
Host Address: the IP address or hostname of the Radiant Agent.
Description:
Radiant Security Agent.Protocol:
TCP.Server Port: the port configured on the Radiant Agent to receive Aruba ClearPass data.
Click Save.
Configure log forwarding on Aruba ClearPass
Each Syslog Export Filter supports one Export Template and one Predefined Field Group, so you create one filter per row in the table below. Use a consistent naming pattern (e.g., Radiant Security <Export Template> - <Predefined Field Group>).
In the Aruba ClearPass console, navigate to Administration > External Servers > Syslog Export Filters.
Click Add.
Enter the following parameters:
Name: a descriptive name following the pattern above (e.g.,
Radiant Security Session Logs - Logged in users).Description:
Radiant Security Syslog Forwarder.Export Template: the Export Template for this filter (e.g.,
Session Logs).Export Event Format Type:
CEF.ClearPass Servers: leave blank.

Click the Filter and Columns tab and configure the following:
Data Filter:
[All Requests].Columns Selection: select the Predefined Field Group that pairs with the Export Template you chose, from the table below.
Click Save.
Repeat steps 2–3 for each Export Template and Predefined Field Group pair in the table.
Export Templates and Predefined Field Groups
Session Logs
Failed Authentications
Session Logs
Guest Access
Session Logs
Logged in users
Session Logs
RADIUS Accounting
Session Logs
TACACS+ Accounting
Insight Logs
Endpoints
Insight Logs
ClearPass Guest
Insight Logs
Onboard Enrollment
Insight Logs
RADIUS Authentications
Insight Logs
RADIUS Failed Authentications
Insight Logs
TACACS Authentication
Insight Logs
TACACS Failed Authentication
Insight Logs
WEBAUTH Failed Authentications
Insight Logs
WEBAUTH
Insight Logs
Application Authentication
Insight Logs
Posture Antivirus Summary
Insight Logs
Posture Antispyware Summary
Insight Logs
Posture DiskEncryption Summary
Insight Logs
Posture Summary
Each Syslog Export Filter can only support one export template and one predefined group. The final result should look like this:

Verify ingestion
After Aruba Clearpass begins forwarding, confirm events are reaching Radiant.
In Radiant, navigate to Log Management.
Filter by
rs_connectorType:"aruba_clearpass".Confirm recent events appear.
Allow several minutes for events to be parsed, indexed, and available for search.
Last updated
Was this helpful?