# Aruba ClearPass (syslog)

In this guide, you will set up a trusted relationship between Radiant and your Aruba ClearPass account to forward logs to Radiant Security via a syslog forwarder.

### Prerequisites

* [ ] Admin access to the Aruba ClearPass console

### Add the data connector in Radiant Security

1. Log in to [Radiant Security](https://app.radiantsecurity.ai/).
2. From the navigation menu, select **Settings** > **Data Connectors** and click **+ Add Connector**.&#x20;
3. Search for and select the **Radiant Agent** option and click **Data Feeds**.&#x20;
4. Under **Select your data feeds**, select **Aruba ClearPass (syslog)** and click **Credentials**.
5. Under **Credential Name**, give the Radiant Agent integration an identifiable name (e.g. `Aruba ClearPass Credentials`) or reuse a pre-existing Radiant Agent integration.
6. Click **Add Connector**.

### Configure a Radiant Agent for log collection

Refer to the [Install the Radiant Security Agent](https://help.radiantsecurity.ai/radiant-connectors/data-connectors/install-the-radiant-security-agent) guide to set up a local agent to collect the logs.

### Adding a syslog target on Aruba ClearPass

1. Access the Aruba ClearPass console.
2. Navigate to **Administration** > **External Servers** > **Syslog Targets.**&#x20;

   <div align="left"><figure><img src="https://2439665791-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FPsFulb2ZOtSPcRSc2rXE%2Fuploads%2FBXKj4i5ICuzSyNBTmGeW%2FAruba%20ClearPass%20(syslog)_05.png?alt=media&#x26;token=f0ead77a-a7d5-469b-b3cd-8cf41f5fabff" alt=""><figcaption></figcaption></figure></div>
3. Click **Add**.
4. Enter the following parameters:
   1. **Host Address**: `<radiant_agent_internal_address>`
   2. **Description**: `Radiant Security On-Prem Log Collector`          &#x20;
   3. **Protocol**: `UDP`
   4. **Server Port**: `<port_configured_to_receive_aruba_clearpass>`\
      &#x20;<img src="https://2439665791-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FPsFulb2ZOtSPcRSc2rXE%2Fuploads%2F4LHuRfZxTRd3Ayw7y7GL%2FAruba%20ClearPass%20(syslog)_06.png?alt=media&#x26;token=db89f98e-5b96-4572-b115-b72592479bef" alt="" data-size="original">
5. Click **Save**.

### Configure log forwarding on Aruba ClearPass

1. Access the Aruba ClearPass console.
2. Navigate to **Administration** > **External Servers** > **Syslog Export Filters.**
3. Click **Add.**
4. Enter the following parameters:
   1. **Name**: `Radiant Security Session Logs - Logged in users`
   2. **Description**: `Radiant Security Syslog Forwarder`
   3. **Export Template**: `Session Logs`
   4. **Export Event Format Type**: `CEF`
   5. **ClearPass Servers**: Leave it blank

      <div align="left"><figure><img src="https://2439665791-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FPsFulb2ZOtSPcRSc2rXE%2Fuploads%2F2K5toXDGveE5mQBvdHOj%2FAruba%20ClearPass%20(syslog)_07.jpg?alt=media&#x26;token=b89533c0-dc1c-48f6-a64b-74b39e16fc48" alt=""><figcaption></figcaption></figure></div>
5. Click the **Filter and Columns** tab and configure the following:

   1. **Data Filter**: `[All Requests]`
   2. **Columns Selection**: Select one of the **Predefined Field Group** values from the table below:

   <table><thead><tr><th width="254.5">Export Template</th><th>Predefined Field Group</th></tr></thead><tbody><tr><td>Session Logs</td><td>Failed Authentications</td></tr><tr><td>Session Logs</td><td>Guest Access</td></tr><tr><td>Session Logs</td><td>Logged in users</td></tr><tr><td>Session Logs</td><td>RADIUS Accounting</td></tr><tr><td>Session Logs</td><td>TACACS+ Accounting</td></tr><tr><td>Insight Logs</td><td>Endpoints</td></tr><tr><td>Insight Logs</td><td>ClearPass Guest</td></tr><tr><td>Insight Logs</td><td>Onboard Enrollment</td></tr><tr><td>Insight Logs</td><td>RADIUS Authentications</td></tr><tr><td>Insight Logs</td><td>RADIUS Failed Authentications</td></tr><tr><td>Insight Logs</td><td>TACACS Authentication</td></tr><tr><td>Insight Logs</td><td>TACACS Failed Authentication</td></tr><tr><td>Insight Logs</td><td>WEBAUTH Failed Authentications</td></tr><tr><td>Insight Logs</td><td>WEBAUTH</td></tr><tr><td>Insight Logs</td><td>Application Authentication</td></tr><tr><td>Insight Logs</td><td>Posture Antivirus Summary</td></tr><tr><td>Insight Logs</td><td>Posture Antispyware Summary</td></tr><tr><td>Insight Logs</td><td>Posture DiskEncryption Summary</td></tr><tr><td>Insight Logs</td><td>Posture Summary</td></tr></tbody></table>
6. Click **Save.**
7. Repeat steps **3 and 4** for all the **Export Templates** and **Predefined Field Group** from the table.
8. Each **Syslog Export Filter** can only support one export template and one predefined group. The final result should look like this:

   <div align="left"><figure><img src="https://2439665791-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FPsFulb2ZOtSPcRSc2rXE%2Fuploads%2F19Zj6PDvG256TZCyHtzg%2FAruba%20ClearPass%20(syslog)_08.png?alt=media&#x26;token=b4154358-95ba-4e81-b16d-7677d8d21796" alt=""><figcaption></figcaption></figure></div>
