Users Guide

CEF Event Format Type > Session Logs
The following example describes the CEF event format type for the Session Logs syslog export filter template:
Dec 01 2017 15:28:40.540 IST 10.17.4.206 CEF:0Dell|ClearPass|6.5.0.68878|1604-1-0|Session
Logs|0|RADIUS.Acct-Calling-Station-Id=00:32:b6:2c:28:95 RADIUS.Acct-Framed-IP-
Address=192.167.230.129 RADIUS.Auth-Source=AD:10.17.4.130 RADIUS.Acct-Timestamp=2014-12-01
15:26:43+05:30 RADIUS.Auth-Method=PAP RADIUS.Acct-Service-Name=Authenticate-Only RADIUS.Acct-
Session-Time=3155 TimestampFormat=MMM dd yyyy HH:mm:ss.SSS zzz RADIUS.Acct-NAS-Port=0
RADIUS.Acct-Session-Id=R00001316-01-547c3b5a RADIUS.Acct-NAS-Port-Type=Wireless-802.11
RADIUS.Acct-Output-Octets=578470212 RADIUS.Acct-Username=A_user2 RADIUS.Acct-NAS-IP-
Address=10.17.6.124 RADIUS.Acct-Input-Octets=786315664
LEEF Event Format Type > Session Logs
The following example describes the LEEF event format type for the Session Logs syslog export filter
template:
Dec 02 2017 15:35:14.944 IST 10.17.4.206 LEEF:1.0Dell|ClearPass|6.5.0.68878|1309854-1-
0|RADIUS.Acct-Calling-Station-Id=00:88:57:2d:12:a4 RADIUS.Acct-Framed-IP-
Address=192.167.203.170 RADIUS.Auth-Source=AD:10.17.4.130 RADIUS.Acct-Timestamp=2017-12-02
15:32:47+05:30 RADIUS.Auth-Method=PAP RADIUS.Acct-Service-Name=Authenticate-Only RADIUS.Acct-
Session-Time=565 TimestampFormat=MMM dd yyyy HH:mm:ss.SSS z RADIUS.Acct-NAS-Port=0
RADIUS.Acct-Session-Id=R000a5038-01-547d8e47 RADIUS.Acct-NAS-Port-Type=Wireless-802.11
RADIUS.Acct-Output-Octets=412895267 RADIUS.Acct-Username=A_user706 RADIUS.Acct-NAS-IP-
Address=10.17.6.124 RADIUS.Acct-Input-Octets=665942581
Filter and Columns Tab
This section describes the parameters in the Filter and Columns page of the Syslog Export Filters > Add
page.
This page provides two methods for configuring data filters: Insight Logs or Session Logs. These methods
are visible only if you select Insight Logs or Session Logs as the export template.
Insight Logs
This section describes the options if you select Insight Logs as the export template in the General tab.
The Insight Logs option is enabled only if you enable Insight on the current W-ClearPass server. To do so, navigate
to the Administration > Server Manager > Server Configuration > System tab, then enable the Enable Insight
check box.
Figure 591 displays the Syslog Export Filters > Filter and Columns > Insight Logs.
Dell Networking W-ClearPass Policy Manager 6.6 | User Guide Administration | 597