Getting Data In

Clearpass App in Splunk not showing data in dashboard

dcarr25
Observer

Hi Community,

Splunk newbie here....

I am trying to set-up a demo of Aruba/HPE Clearpass to Splunk integration.

I have configured Clearpass to send syslog (udp-514) to Splunk for Audit records on Clearpass. I have also installed the Clearpass App in Splunk, set-up a Data Input and can see syslog events hitting the Splunk server when using Wireshark. I have also set-up a new index 'aruba' and can see that this is being populated frequently, however I do not see any events in the Splunk dashboard for the Clearpass App. 

Any idea what could be causing this? 

Splunk is installed on a Windows 2019 server in my home lab that is also my lab AD domain controller (I only have one server license). 

Thanks

Tags (1)
0 Karma
Get Updates on the Splunk Community!

Community Content Calendar, November Edition

Welcome to the November edition of our Community Spotlight! Each month, we dive into the Splunk Community to ...

October Community Champions: A Shoutout to Our Contributors!

As October comes to a close, we want to take a moment to celebrate the people who make the Splunk Community ...

Stay Connected: Your Guide to November Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...