# Aruba ClearPass (syslog)

In this guide, you will set up a trusted relationship between Radiant and your Aruba ClearPass account to forward logs to Radiant Security via a syslog forwarder.

### Prerequisites

* [ ] Admin access to the Aruba ClearPass console

### Add the data connector in Radiant Security

1. Log in to [Radiant Security](https://app.radiantsecurity.ai/).
2. From the navigation menu, select **Settings** > **Data Connectors** and click **+ Add Connector**.&#x20;
3. Search for and select the **Radiant Agent** option and click **Data Feeds**.&#x20;
4. Under **Select your data feeds**, select **Aruba ClearPass (syslog)** and click **Credentials**.
5. Under **Credential Name**, give the Radiant Agent integration an identifiable name (e.g. `Aruba ClearPass Credentials`) or reuse a pre-existing Radiant Agent integration.
6. Click **Add Connector**.

### Configure a Radiant Agent for log collection

Refer to the [Install the Radiant Security Agent](https://help.radiantsecurity.ai/radiant-connectors/data-connectors/install-the-radiant-security-agent) guide to set up a local agent to collect the logs.

### Adding a syslog target on Aruba ClearPass

1. Access the Aruba ClearPass console.
2. Navigate to **Administration** > **External Servers** > **Syslog Targets.**&#x20;

   <div align="left"><figure><img src="https://2439665791-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FPsFulb2ZOtSPcRSc2rXE%2Fuploads%2FBXKj4i5ICuzSyNBTmGeW%2FAruba%20ClearPass%20(syslog)_05.png?alt=media&#x26;token=f0ead77a-a7d5-469b-b3cd-8cf41f5fabff" alt=""><figcaption></figcaption></figure></div>
3. Click **Add**.
4. Enter the following parameters:
   1. **Host Address**: `<radiant_agent_internal_address>`
   2. **Description**: `Radiant Security On-Prem Log Collector`          &#x20;
   3. **Protocol**: `UDP`
   4. **Server Port**: `<port_configured_to_receive_aruba_clearpass>`\
      &#x20;<img src="https://2439665791-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FPsFulb2ZOtSPcRSc2rXE%2Fuploads%2F4LHuRfZxTRd3Ayw7y7GL%2FAruba%20ClearPass%20(syslog)_06.png?alt=media&#x26;token=db89f98e-5b96-4572-b115-b72592479bef" alt="" data-size="original">
5. Click **Save**.

### Configure log forwarding on Aruba ClearPass

1. Access the Aruba ClearPass console.
2. Navigate to **Administration** > **External Servers** > **Syslog Export Filters.**
3. Click **Add.**
4. Enter the following parameters:
   1. **Name**: `Radiant Security Session Logs - Logged in users`
   2. **Description**: `Radiant Security Syslog Forwarder`
   3. **Export Template**: `Session Logs`
   4. **Export Event Format Type**: `CEF`
   5. **ClearPass Servers**: Leave it blank

      <div align="left"><figure><img src="https://2439665791-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FPsFulb2ZOtSPcRSc2rXE%2Fuploads%2F2K5toXDGveE5mQBvdHOj%2FAruba%20ClearPass%20(syslog)_07.jpg?alt=media&#x26;token=b89533c0-dc1c-48f6-a64b-74b39e16fc48" alt=""><figcaption></figcaption></figure></div>
5. Click the **Filter and Columns** tab and configure the following:

   1. **Data Filter**: `[All Requests]`
   2. **Columns Selection**: Select one of the **Predefined Field Group** values from the table below:

   <table><thead><tr><th width="254.5">Export Template</th><th>Predefined Field Group</th></tr></thead><tbody><tr><td>Session Logs</td><td>Failed Authentications</td></tr><tr><td>Session Logs</td><td>Guest Access</td></tr><tr><td>Session Logs</td><td>Logged in users</td></tr><tr><td>Session Logs</td><td>RADIUS Accounting</td></tr><tr><td>Session Logs</td><td>TACACS+ Accounting</td></tr><tr><td>Insight Logs</td><td>Endpoints</td></tr><tr><td>Insight Logs</td><td>ClearPass Guest</td></tr><tr><td>Insight Logs</td><td>Onboard Enrollment</td></tr><tr><td>Insight Logs</td><td>RADIUS Authentications</td></tr><tr><td>Insight Logs</td><td>RADIUS Failed Authentications</td></tr><tr><td>Insight Logs</td><td>TACACS Authentication</td></tr><tr><td>Insight Logs</td><td>TACACS Failed Authentication</td></tr><tr><td>Insight Logs</td><td>WEBAUTH Failed Authentications</td></tr><tr><td>Insight Logs</td><td>WEBAUTH</td></tr><tr><td>Insight Logs</td><td>Application Authentication</td></tr><tr><td>Insight Logs</td><td>Posture Antivirus Summary</td></tr><tr><td>Insight Logs</td><td>Posture Antispyware Summary</td></tr><tr><td>Insight Logs</td><td>Posture DiskEncryption Summary</td></tr><tr><td>Insight Logs</td><td>Posture Summary</td></tr></tbody></table>
6. Click **Save.**
7. Repeat steps **3 and 4** for all the **Export Templates** and **Predefined Field Group** from the table.
8. Each **Syslog Export Filter** can only support one export template and one predefined group. The final result should look like this:

   <div align="left"><figure><img src="https://2439665791-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FPsFulb2ZOtSPcRSc2rXE%2Fuploads%2F19Zj6PDvG256TZCyHtzg%2FAruba%20ClearPass%20(syslog)_08.png?alt=media&#x26;token=b4154358-95ba-4e81-b16d-7677d8d21796" alt=""><figcaption></figcaption></figure></div>


---

# Agent Instructions: Querying This Documentation

If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter:

```
GET https://help.radiantsecurity.ai/radiant-connectors/data-connectors/aruba-clearpass-syslog.md?ask=<question>
```

The question should be specific, self-contained, and written in natural language.
The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
