Aruba ClearPass (syslog)
Configure ClearPass Policy Manager to forward syslog logs to Radiant Security.
In this guide, you will set up a trusted relationship between Radiant and your Aruba ClearPass account to forward logs to Radiant Security via a syslog forwarder.
Prerequisites
Add the data connector in Radiant Security
Log in to Radiant Security.
From the navigation menu, select Settings > Data Connectors and click + Add Connector.
Search for and select the Aruba ClearPass (syslog) option and click Data Feeds.
Under Select your data feeds, select Aruba ClearPass (syslog) and click Credentials.
Under Credential Name, give the credential an identifiable name (e.g.
Aruba ClearPass Credentials
) then, click Credentials.Under Required Credentials, enter a value for the Connector Tag. This can be any string you want.
Click Add Connector to save the changes.
Copy and save the connector Token value using the clipboard option or use the Download File option to save it as a SSL certificate or token file. You will need this token to complete the configuration.
Click Done to save your changes.
Configure a Radiant Agent for log collection
Refer to the Install the Radiant Security Agent guide to set up a local agent to collect the logs.
Adding a syslog target on Aruba ClearPass
Access the Aruba ClearPass console.
Navigate to Administration > External Servers > Syslog Targets.
Click Add.
Enter the following parameters:
Host Address:
<syslog_collector_internal_address>
Description:
Radiant Security On-Prem Syslog Forwarder
Protocol:
UDP
Server Port:
514
Click Save.
Configure log forwarding on Aruba ClearPass
Access the Aruba ClearPass console.
Navigate to Administration > External Servers > Syslog Export Filters.
Click Add.
Enter the following parameters:
Name:
Radiant Security Session Logs - Logged in users
Description:
Radiant Security Syslog Forwarder
Export Template:
Session Logs
Export Event Format Type:
CEF
ClearPass Servers: Leave it blank
Click the Filter and Columns tab and configure the following:
Data Filter:
[All Requests]
Columns Selection: Select one of the Predefined Field Group values from the table below:
Export TemplatePredefined Field GroupSession Logs
Failed Authentications
Session Logs
Guest Access
Session Logs
Logged in users
Session Logs
RADIUS Accounting
Session Logs
TACACS+ Accounting
Insight Logs
Endpoints
Insight Logs
ClearPass Guest
Insight Logs
Onboard Enrollment
Insight Logs
RADIUS Authentications
Insight Logs
RADIUS Failed Authentications
Insight Logs
TACACS Authentication
Insight Logs
TACACS Failed Authentication
Insight Logs
WEBAUTH Failed Authentications
Insight Logs
WEBAUTH
Insight Logs
Application Authentication
Insight Logs
Posture Antivirus Summary
Insight Logs
Posture Antispyware Summary
Insight Logs
Posture DiskEncryption Summary
Insight Logs
Posture Summary
Click Save.
Repeat steps 3 and 4 for all the Export Templates and Predefined Field Group from the table.
Each Syslog Export Filter can only support one export template and one predefined group. The final result should look like this:
Last updated