<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How do I send TACACS+ logs from TACACS+ Server to a remote Syslog server? in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/how-do-i-send-tacacs-logs-from-tacacs-server-to-a-remote-syslog/m-p/3414858#M547953</link>
    <description>&lt;P&gt;Please, I need an urgent assistance.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am new to TACACS and I have this assignment to come up with a process to send TACACS+ logs from a client's TACACS+ server to a remote Syslog server where we can take the information into our&amp;nbsp;SIEM for correlation and review.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;U&gt;A Brief Overview&lt;/U&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;The client has a couple of CISCO switches. The individual switches in the client's network infrastructure use a Solaris TACACS+ server as the source for authentication. When logging Privileged User activity, our SIEM does not collect logs from any individual switch but collects them from the central TACACS+ server. TACACS+ logs can be retrieved by the SIEM infrastructure based upon the TACAS+ server using the Syslog push file transfer protocol. This method sends log messages from the TACACS+ server to a remote syslog server from where the SIEM will ingest the logs.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;U&gt;&lt;STRONG&gt;Request&lt;/STRONG&gt;&lt;/U&gt;&lt;/P&gt;
&lt;P&gt;Please, I need to know the line to add to the Solaris &lt;EM&gt;etc/syslog.conf&lt;/EM&gt; file on the TACACS+ server that will activate the TACACS+ log forwarding from Solaris TACACS+ server to the Syslog server.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I will appreciate a quick solution.&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 19:00:51 GMT</pubDate>
    <dc:creator>chimobinwoko@yahoo.com</dc:creator>
    <dc:date>2020-02-21T19:00:51Z</dc:date>
    <item>
      <title>How do I send TACACS+ logs from TACACS+ Server to a remote Syslog server?</title>
      <link>https://community.cisco.com/t5/network-access-control/how-do-i-send-tacacs-logs-from-tacacs-server-to-a-remote-syslog/m-p/3414858#M547953</link>
      <description>&lt;P&gt;Please, I need an urgent assistance.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am new to TACACS and I have this assignment to come up with a process to send TACACS+ logs from a client's TACACS+ server to a remote Syslog server where we can take the information into our&amp;nbsp;SIEM for correlation and review.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;U&gt;A Brief Overview&lt;/U&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;The client has a couple of CISCO switches. The individual switches in the client's network infrastructure use a Solaris TACACS+ server as the source for authentication. When logging Privileged User activity, our SIEM does not collect logs from any individual switch but collects them from the central TACACS+ server. TACACS+ logs can be retrieved by the SIEM infrastructure based upon the TACAS+ server using the Syslog push file transfer protocol. This method sends log messages from the TACACS+ server to a remote syslog server from where the SIEM will ingest the logs.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;U&gt;&lt;STRONG&gt;Request&lt;/STRONG&gt;&lt;/U&gt;&lt;/P&gt;
&lt;P&gt;Please, I need to know the line to add to the Solaris &lt;EM&gt;etc/syslog.conf&lt;/EM&gt; file on the TACACS+ server that will activate the TACACS+ log forwarding from Solaris TACACS+ server to the Syslog server.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I will appreciate a quick solution.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 19:00:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-do-i-send-tacacs-logs-from-tacacs-server-to-a-remote-syslog/m-p/3414858#M547953</guid>
      <dc:creator>chimobinwoko@yahoo.com</dc:creator>
      <dc:date>2020-02-21T19:00:51Z</dc:date>
    </item>
    <item>
      <title>Re: How do I send TACACS+ logs from TACACS+ Server to a remote Syslog server?</title>
      <link>https://community.cisco.com/t5/network-access-control/how-do-i-send-tacacs-logs-from-tacacs-server-to-a-remote-syslog/m-p/3415013#M547955</link>
      <description>&lt;P&gt;Add this below line :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;*.err;kern.debug&amp;nbsp; &amp;nbsp; &amp;nbsp;@192.168.1.1&amp;nbsp; (192.168.1.1 is the syslog server where you send the messages - eample sending err and kernel messages to syslog server)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;restart system-log&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;and test it&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;BB&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 12 Jul 2018 22:13:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-do-i-send-tacacs-logs-from-tacacs-server-to-a-remote-syslog/m-p/3415013#M547955</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2018-07-12T22:13:43Z</dc:date>
    </item>
    <item>
      <title>Re: How do I send TACACS+ logs from TACACS+ Server to a remote Syslog server?</title>
      <link>https://community.cisco.com/t5/network-access-control/how-do-i-send-tacacs-logs-from-tacacs-server-to-a-remote-syslog/m-p/3415020#M547957</link>
      <description>Thank you very much &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/286878"&gt;@balaji.bandi&lt;/a&gt;. I am very grateful. You have given me a great solution.&lt;BR /&gt;&lt;BR /&gt;But if I want to send only AAA events from TACACS+, what syslog facilities do I reference? That is instead of sending kernel and err messages, I send only TACACS+ Authentication and Authorization logs.&lt;BR /&gt;</description>
      <pubDate>Thu, 12 Jul 2018 23:04:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-do-i-send-tacacs-logs-from-tacacs-server-to-a-remote-syslog/m-p/3415020#M547957</guid>
      <dc:creator>chimobinwoko@yahoo.com</dc:creator>
      <dc:date>2018-07-12T23:04:41Z</dc:date>
    </item>
    <item>
      <title>Re: How do I send TACACS+ logs from TACACS+ Server to a remote Syslog server?</title>
      <link>https://community.cisco.com/t5/network-access-control/how-do-i-send-tacacs-logs-from-tacacs-server-to-a-remote-syslog/m-p/3416004#M547958</link>
      <description>&lt;P&gt;&lt;SPAN&gt;logging level aaa 6&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;BB&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 15 Jul 2018 20:58:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-do-i-send-tacacs-logs-from-tacacs-server-to-a-remote-syslog/m-p/3416004#M547958</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2018-07-15T20:58:38Z</dc:date>
    </item>
  </channel>
</rss>

