Link to home
Start Free TrialLog in
Avatar of amigan_99
amigan_99Flag for United States of America

asked on

Cisco ACS: How to send all radius and tacacs auth information to syslog

When I look at Splunk - where I send my Cisco ACS 5.4 syslog output - I see a record of actions I've done on ACS. But I'm not seeing the TACACS records when I log into various network devices. I can see the tacacs records if I go to Monitoring and Reports section of ACS. How can I view in syslog?
ASKER CERTIFIED SOLUTION
Avatar of atlas_shuddered
atlas_shuddered
Flag of United States of America image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Please clarify your request, do you want logon events forwarded to syslog as well?
The link might address it where you specify which events you want logged ...
Another option you could setup snmptrap and send snmptraps to it with events ...
You could log the events on the server where nps is running.
Avatar of amigan_99

ASKER

Thank you