Avatar of amigan_99
amigan_99
Flag for United States of America asked on

Cisco ACS: How to send all radius and tacacs auth information to syslog

When I look at Splunk - where I send my Cisco ACS 5.4 syslog output - I see a record of actions I've done on ACS. But I'm not seeing the TACACS records when I log into various network devices. I can see the tacacs records if I go to Monitoring and Reports section of ACS. How can I view in syslog?
NetworkingSecurityNetworking Hardware-OtherRoutersHardware Firewalls

Avatar of undefined
Last Comment
amigan_99

8/22/2022 - Mon
ASKER CERTIFIED SOLUTION
atlas_shuddered

THIS SOLUTION ONLY AVAILABLE TO MEMBERS.
View this solution by signing up for a free trial.
Members can start a 7-Day free trial and enjoy unlimited access to the platform.
See Pricing Options
Start Free Trial
GET A PERSONALIZED SOLUTION
Ask your own question & get feedback from real experts
Find out why thousands trust the EE community with their toughest problems.
arnold

Please clarify your request, do you want logon events forwarded to syslog as well?
The link might address it where you specify which events you want logged ...
Another option you could setup snmptrap and send snmptraps to it with events ...
arnold

You could log the events on the server where nps is running.
amigan_99

ASKER
Thank you
Your help has saved me hundreds of hours of internet surfing.
fblack61