On 26.2.2020 22.25, Ullfig, Roberto Alfredo wrote:

Does there exist a Splunk plugin for Radiator logging (the <AuthLog> stanza)? Right now some of this information is logged only remotely via SYSLOG (no local logs) and so our locally running Splunk Forwarder is not picking it up. Thanks!

You could consider logging to a file, possibly in JSON format. That would allow the forwarder to use the log file as data inputfrom the local file system. See goodies/logformat.cfg and look for 'myauthlogger-json'. The top of the file has notes about custom formats, if needed.

Or would the requirement be that no log touches the file system with Radiator providing a listen port for a forwarder to connect to?

Thanks,
Heikki

--
Heikki Vatiainen <[email protected]>

Radiator: the most portable, flexible and configurable RADIUS server
anywhere. SQL, proxy, DBM, files, LDAP, TACACS+, PAM, Active Directory,
EAP, TLS, TTLS, PEAP, WiMAX, RSA, Vasco, Yubikey, HOTP, TOTP,
DIAMETER etc. Full source on Unix, Windows, MacOSX, Solaris, VMS, etc.
_______________________________________________
radiator mailing list
[email protected]
https://lists.open.com.au/mailman/listinfo/radiator

Reply via email to