Resolution
Complete these steps in order to capture the event logs and send those to another server for archiving and investigation:
- Log on to the Cisco Clean Access Manager (CAM) as root.
- Issue the psql -h 127.0.0.1 controlsmartdb -U postgres command.
- Issue the \a command.
- Issue the \o /root/LogInformationTable command.
- Choose * from log_info. Make sure you put the semi-colon ; in, otherwise it does not work.
- Issue the \q command.
- Track the LogInformationTable file in your root directory, which holds all your records from the log_info table from the database. This file is in text format too, delimited by the | character.
- Enable syslog and capture the events on the syslog.
Refer to Clean Access Manager Installation and Administration Guide for more information.
Refer How to configure Clean Access Manager (CAM) to report events to Cisco Secure Monitoring Analysis and Response System (CS-MARS) for more information on how to configure Clean Access Manager in order to report events to Cisco Security Monitoring, Analysis and Response System (CS-MARS).