Filter and Columns Tab

This section describes the parameters in the Filter and Columns page of the Syslog Export Filters > Add page.

This page provides two methods for configuring data filters: Insight Logs or Session Logs. These methods are visible only if you select Insight Logs or Session Logs as the export template.

Insight Logs

This section describes the options if you select Insight Logs as the export template in the General tab.

 

The Insight Logs option is enabled only if you enable Insight on the current ClearPass server. To do so, navigate to the Administration > Server Manager > Server Configuration > System tab, then enable the Enable Insight check box.

Figure 1 displays the Syslog Export Filters > Filter and Columns > Insight Logs.

Figure 1  Syslog Export Filters > Filter and Columns >Insight Logs

As shown in Figure 1, administrators can select EndpointTag attributes as a column in Syslog Export Filters.

Custom attributes fetched by users and recorded in an endpoint are sent in syslog export filters to the Syslog server. When there is a update on endpoints, syslog events are generated.

 

The data collection interval for Insight logs is -4 to -2 minutes from the current time.

Specify the Syslog Export Filters > Filter and Columns > Insight Logs parameters as described in the following table:

Table 1: Syslog Export Filters > Filter and Columns > Insight Logs Parameters

Parameter

Action/Description

Columns Selection

Determine the group of reports that you want to include in the syslog filters. The column selection limits the type of records sent to the syslog filters.

NOTE: You can add only the Insight reports that are already created in Insight. You cannot create a new data filter for Insight logs.

Predefined Field Groups

Select the predefined Insight reports that are grouped for addition.

Selected Columns

After you select an entry from the Available Columns list, click >> to add the selected entry to the Selected Columns list. Click << to remove an entry from the Selected Columns list.

Session Logs

This section describes the options if you select Session Logs as the export template in the General tab. On selecting Session Logs, the following options are available:

Option 1 allows you to choose from pre-defined field groups and to select columns based on the Type.

Option 2 allows you to create a custom SQL query. You can view a sample template for the custom SQL by clicking the link below the text entry field.

 

It is recommended to contact support if you choose the option 2. Support can assist you with entering the correct information in this template.

The following figure displays the Syslog Export Filters - Filter and Columns (Session Logs) tab.

Figure 2  Syslog Export Filters - Filter and Columns (Session Logs) Tab

The following table describes the Syslog Export Filters > Filter and Columns > Session Logs parameters:

Table 2: Syslog Export Filters > Filter and Columns > Insight Logs Parameters

Parameter

Action/Description

Data Filter

Specify the data filter. The data filter limits the type of records sent to the syslog target.

Modify/ Add New Data Filter

Modify the selected data filter, or add a new one.

Specifying a data filter filters the rows that are sent to the syslog target. You may also select the columns that are sent to the syslog target. For more information on adding a data filter, see Adding a Data Filter .

Columns Selection

The column selection limits the type of columns sent to the syslog target.

There are predefined field groups, which are column names grouped together for quick addition to the report. For example, Logged in users field group has seven predefined columns. When you click Logged in users the seven columns automatically appear in the Selected Columns list.

Additional fields are available to add to the reports. You can select the type of attributes (which are the different table columns available in the session database) from the Available Columns Type drop down list. Policy Manager populates these column names by extracting the column names from existing sessions in the session database.

After you select an entry from the Available Columns list, click >> to add the selected entry to the Selected Columns list.

Click << to remove an entry from the Selected Columns list.

Custom SQL

Specify custom SQL query for export. This option is for advanced use cases.

NOTE: If you choose this option, contact Aruba Support at Administration > Support > Contact Support. Support can assist you with entering the correct information in this template.