<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Clearpass app not displaying important field in dashboards in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Clearpass-app-not-displaying-important-field-in-dashboards/m-p/433109#M95840</link>
    <description>&lt;P&gt;I'm not sure the field alias is the right issue.  There are no "interesting fields" that would even hint as a user_name. or any of the other issues at top.  It just isn't parsing the fields appropriately to generate the "interesting fields".&lt;/P&gt;</description>
    <pubDate>Tue, 11 Dec 2018 23:02:44 GMT</pubDate>
    <dc:creator>Iwdavies</dc:creator>
    <dc:date>2018-12-11T23:02:44Z</dc:date>
    <item>
      <title>Clearpass app not displaying important field in dashboards</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Clearpass-app-not-displaying-important-field-in-dashboards/m-p/433106#M95837</link>
      <description>&lt;P&gt;The Clearpass app is displaying data, however, it is missing populating major fields.  when I look at the Search I also see these field missing in the search interesting fields, even though these fields exist in the raw data.  Here is a list of the missing fields:&lt;/P&gt;

&lt;P&gt;user_name&lt;BR /&gt;
mac_addrees&lt;BR /&gt;
ip_address&lt;BR /&gt;
mac_vendor&lt;/P&gt;

&lt;P&gt;There may be more but it just appears that the indexer isn't indexing these fields....&lt;/P&gt;

&lt;P&gt;Any ideas?&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 22:22:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Clearpass-app-not-displaying-important-field-in-dashboards/m-p/433106#M95837</guid>
      <dc:creator>Iwdavies</dc:creator>
      <dc:date>2020-09-29T22:22:41Z</dc:date>
    </item>
    <item>
      <title>Re: Clearpass app not displaying important field in dashboards</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Clearpass-app-not-displaying-important-field-in-dashboards/m-p/433107#M95838</link>
      <description>&lt;P&gt;What version of Splunk are you on...??&lt;BR /&gt;
If you are on 7.2 and above, there is a change in Fieldalias behavior, you might have to check you props.conf...&lt;/P&gt;

&lt;P&gt;&lt;A href="https://answers.splunk.com/answers/693737/splunk-720-field-aliases-incorrect-behavior.html"&gt;https://answers.splunk.com/answers/693737/splunk-720-field-aliases-incorrect-behavior.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 10 Dec 2018 20:04:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Clearpass-app-not-displaying-important-field-in-dashboards/m-p/433107#M95838</guid>
      <dc:creator>prakash007</dc:creator>
      <dc:date>2018-12-10T20:04:06Z</dc:date>
    </item>
    <item>
      <title>Re: Clearpass app not displaying important field in dashboards</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Clearpass-app-not-displaying-important-field-in-dashboards/m-p/433108#M95839</link>
      <description>&lt;P&gt;We are using 7.2.  I'm looking at the information you supplied and it is probably on the right track.  I just don't know splunk well enough to understand how to configure the props.conf file and what the Fieldalias configs should look like.  I'll write back when I know if that is the problem or not.&lt;/P&gt;</description>
      <pubDate>Mon, 10 Dec 2018 22:08:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Clearpass-app-not-displaying-important-field-in-dashboards/m-p/433108#M95839</guid>
      <dc:creator>Iwdavies</dc:creator>
      <dc:date>2018-12-10T22:08:35Z</dc:date>
    </item>
    <item>
      <title>Re: Clearpass app not displaying important field in dashboards</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Clearpass-app-not-displaying-important-field-in-dashboards/m-p/433109#M95840</link>
      <description>&lt;P&gt;I'm not sure the field alias is the right issue.  There are no "interesting fields" that would even hint as a user_name. or any of the other issues at top.  It just isn't parsing the fields appropriately to generate the "interesting fields".&lt;/P&gt;</description>
      <pubDate>Tue, 11 Dec 2018 23:02:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Clearpass-app-not-displaying-important-field-in-dashboards/m-p/433109#M95840</guid>
      <dc:creator>Iwdavies</dc:creator>
      <dc:date>2018-12-11T23:02:44Z</dc:date>
    </item>
    <item>
      <title>Re: Clearpass app not displaying important field in dashboards</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Clearpass-app-not-displaying-important-field-in-dashboards/m-p/433110#M95841</link>
      <description>&lt;P&gt;Here is an example of information in the log.  bolded fields don't appear in the interesting fields section and x's have been used to replace certain values:&lt;/P&gt;

&lt;P&gt;Dec 11 14:55:48 x.x.x.x 2018-12-11 14:55:48,962 x.x.x.x CPPM_Dashboard_Summary 2957 1 0 session_id=R00005531-01-5c10400b,req_source=RADIUS,user_name=xxxxxx,service_name=Employee Onboarding Onboard Provisioning,alerts_present=0,&lt;STRONG&gt;nas_ip=x.x.x.x&lt;/STRONG&gt;,&lt;STRONG&gt;nas_port=0&lt;/STRONG&gt;,conn_status=Unknown,login_status=ACCEPT,error_code=0,&lt;STRONG&gt;mac_address=xxxxxxxxxxxx&lt;/STRONG&gt;,timestamp=2018-12-11 14:54:04-08,write_timestamp=2018-12-11 14:54:05.435015-08&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 22:23:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Clearpass-app-not-displaying-important-field-in-dashboards/m-p/433110#M95841</guid>
      <dc:creator>Iwdavies</dc:creator>
      <dc:date>2020-09-29T22:23:29Z</dc:date>
    </item>
    <item>
      <title>Re: Clearpass app not displaying important field in dashboards</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Clearpass-app-not-displaying-important-field-in-dashboards/m-p/433111#M95842</link>
      <description>&lt;P&gt;Here is an example of data that is being indexed but certain fields are missing from the "interesting fields".  I have placed xxxx to remove certain data.  Fields that are bold don't appear in the interesting field list:&lt;/P&gt;

&lt;P&gt;Dec 11 14:55:48 x.x.x.x 2018-12-11 14:55:48,962 x.x.x.x CPPM_Dashboard_Summary 2957 1 0 session_id=R00005531-01-5c10400b,req_source=RADIUS,&lt;STRONG&gt;user_name=xxxxxxx&lt;/STRONG&gt;,service_name=Employee Onboarding Onboard Provisioning,alerts_present=0,&lt;STRONG&gt;nas_ip=x.x.x.x&lt;/STRONG&gt;,&lt;STRONG&gt;nas_port=0&lt;/STRONG&gt;,conn_status=Unknown,login_status=ACCEPT,error_code=0,&lt;STRONG&gt;mac_address=xxxxxxxxxxxx&lt;/STRONG&gt;,timestamp=2018-12-11 14:54:04-08,write_timestamp=2018-12-11 14:54:05.435015-08&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 22:23:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Clearpass-app-not-displaying-important-field-in-dashboards/m-p/433111#M95842</guid>
      <dc:creator>Iwdavies</dc:creator>
      <dc:date>2020-09-29T22:23:31Z</dc:date>
    </item>
    <item>
      <title>Re: Clearpass app not displaying important field in dashboards</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Clearpass-app-not-displaying-important-field-in-dashboards/m-p/433112#M95843</link>
      <description>&lt;P&gt;when you look into your clearpass app in splunk, you can see the missing fields that are aliased here... i.e $SPLUNK_HOME/etc/apps/ClearPassOnSplunk_2/default/props.conf..&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;FIELDALIAS-cppm-24 = framed_ip_address AS ip_address
FIELDALIAS-cppm-016 = username as user_name
FIELDALIAS-cppm-acctnasip = nas_ip_address AS nas_ip
FIELDALIAS-cppm-019 = nad_ip AS nas_ip
FIELDALIAS-cppm-910 = host_mac AS mac_address
FIELDALIAS-cppm-911 = end_host_id AS mac_address
FIELDALIAS-cppm-911 = mac_address AS end_host_id
#FIELDALIAS-cppm-host = ClearPass_Server AS host
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Let's take  FIELDALIAS-cppm-24 = framed_ip_address AS ip_address, in this case you need to have either ip_address or framed_ip_address in your raw data, due to a change in FIELDALIAS behavior in 7.2...you have to change your configs like this...&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;#FIELDALIAS-cppm-24 = framed_ip_address AS ip_address
EVAL-ip_address = coalesce(ip_address, framed_ip_address)
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;so, before making any changes, I would check the raw logs on the source host(may be a syslog) to make sure I have the required fields in the log file itself or Splunk is not parsing the fields correctly...??&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 22:20:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Clearpass-app-not-displaying-important-field-in-dashboards/m-p/433112#M95843</guid>
      <dc:creator>prakash007</dc:creator>
      <dc:date>2020-09-29T22:20:35Z</dc:date>
    </item>
  </channel>
</rss>

