Aruba Clearpass Integration Threat Logs
Does anybody have experience configuring Clearpass to ingest Threat Syslog from Palo Alto? I am struggling to get Clearpass to correctly parse the Syslog and was wondering if anybody has an example definition/format for the Palo Alto as well as Clearpass side that has worked before. Currently I see the logs making it to the Clearpass IngressProc log but everything is stuck in the “message” field and unable to parse the logs.
u/KR-Rails — 5 days ago