Hi Community,
Splunk newbie here....
I am trying to set-up a demo of Aruba/HPE Clearpass to Splunk integration.
I have configured Clearpass to send syslog (udp-514) to Splunk for Audit records on Clearpass. I have also installed the Clearpass App in Splunk, set-up a Data Input and can see syslog events hitting the Splunk server when using Wireshark. I have also set-up a new index 'aruba' and can see that this is being populated frequently, however I do not see any events in the Splunk dashboard for the Clearpass App.
Any idea what could be causing this?
Splunk is installed on a Windows 2019 server in my home lab that is also my lab AD domain controller (I only have one server license).
Thanks