When going to v7.2.x+ from 7.1.x You will want to comment out the below fields, that is in the default/props.conf that will not show up as a field extraction.
This is the only anomaly so far that has come up after upgrading to v7.2.3 from v7.1.0
$splunk_homedir/splunk/etc/apps/ClearPassOnSplunk_2/default/props.conf
Field Aliases
commenting out remaining aliases to isolate missing field extractions
FIELDALIAS-cppm-24 = framed_ip_address AS ip_address
FIELDALIAS-cppm-016 = username as user_name
FIELDALIAS-cppm-acctnasip = nas_ip_address AS nas_ip
FIELDALIAS-cppm-019 = nad_ip AS nas_ip
FIELDALIAS-cppm-910 = host_mac AS mac_address
FIELDALIAS-cppm-911 = end_host_id AS mac_address
FIELDALIAS-cppm-911 = mac_address AS end_host_id
FIELDALIAS-cppm-host = ClearPass_Server AS host
... View more