[RADIATOR] Splunk Plugin for Radiator?
Heikki Vatiainen
hvn at open.com.au
Thu Feb 27 12:15:33 UTC 2020
On 26.2.2020 22.25, Ullfig, Roberto Alfredo wrote:
> Does there exist a Splunk plugin for Radiator logging (the <AuthLog>
> stanza)? Right now some of this information is logged only remotely via
> SYSLOG (no local logs) and so our locally running Splunk Forwarder is
> not picking it up. Thanks!
You could consider logging to a file, possibly in JSON format. That
would allow the forwarder to use the log file as data inputfrom the
local file system. See goodies/logformat.cfg and look for
'myauthlogger-json'. The top of the file has notes about custom formats,
if needed.
Or would the requirement be that no log touches the file system with
Radiator providing a listen port for a forwarder to connect to?
Thanks,
Heikki
--
Heikki Vatiainen <hvn at open.com.au>
Radiator: the most portable, flexible and configurable RADIUS server
anywhere. SQL, proxy, DBM, files, LDAP, TACACS+, PAM, Active Directory,
EAP, TLS, TTLS, PEAP, WiMAX, RSA, Vasco, Yubikey, HOTP, TOTP,
DIAMETER etc. Full source on Unix, Windows, MacOSX, Solaris, VMS, etc.
More information about the radiator
mailing list