Hello Aforsythe,
I am so glad to receive a reply. I’ve been trying to work on this in between juggling many projects. I am only working with the Kiwi Syslog Server logs and not firewall logs. And we are logging for any device connecting to wireless: Android, iPhone, Windows, etc.
I have filtered for the enterprise=1.3.6.1.4.1.9.9.599.0.8, enterprise_mib_name=ciscoLwappDot11ClientSessionTrap
This is the information that I need in order to identify Internet traffic for a device. I need the device IP address and the device MAC address. I like to also see the AP collecting the data and which WLAN is in use and the ciscoLwappDot11ClientSessionTrap mib includes all this data, but the IP Address is not formatted correctly.
Note that the IP Address is not logging the correct format. Note also that sometimes it does, but most times it does not. How can I consistently capture the IP Address in the correct format?
Thank you so very much for your help,
Karen
SyslogCatchAll_KIWI-2019-03-06.txt
2019-03-06 07:46:41 Auth.Debug 172.30.1.44 community=2504SNMPLogs, enterprise=1.3.6.1.4.1.9.9.599.0.8, enterprise_mib_name=ciscoLwappDot11ClientSessionTrap, uptime=359298400, agent_ip=172.30.1.44, version=Ver2,
1.3.6.1.4.1.9.9.513.1.2.1.1.1.0=1, cLApDot11IfSlotId.0=1,
1.3.6.1.4.1.9.9.513.1.1.1.1.5.32.76.158.234.79.176=RT13-Office-AP2, cLApName.32.76.158.234.79.176=RT13-Office-AP2,
1.3.6.1.4.1.9.9.599.1.3.2.1.2.0=1, cldcClientByIpAddressType.0=1,
1.3.6.1.4.1.9.9.599.1.3.2.1.3.0=ª<030><001>G, cldcClientByIpAddress.0=ª<030><001>G, 1.3.6.1.4.1.9.9.599.1.3.1.1.27.140.69.0.171.27.33=, cldcClientUsername.140.69.0.171.27.33=, 1.3.6.1.4.1.9.9.599.1.3.1.1.28.140.69.0.171.27.33=JMMurrayRT13, cldcClientSSID.140.69.0.171.27.33=JMMurrayRT13, 1.3.6.1.4.1.9.9.599.1.3.1.1.38.140.69.0.171.27.33=5c7fc131/8c:45:00:ab:1b:21/7408, cldcClientSessionID.140.69.0.171.27.33=5c7fc131/8c:45:00:ab:1b:21/7408,
1.3.6.1.4.1.9.9.599.1.3.1.1.8.140.69.0.171.27.33=20:4C:9E:EA:4F:B0, cldcApMacAddress.140.69.0.171.27.33=20:4C:9E:EA:4F:B0
2019-03-06 08:02:20 Auth.Debug 172.30.1.44 community=2504SNMPLogs, enterprise=1.3.6.1.4.1.9.9.599.0.8, enterprise_mib_name=ciscoLwappDot11ClientSessionTrap, uptime=359392300, agent_ip=172.30.1.44, version=Ver2,
1.3.6.1.4.1.9.9.513.1.2.1.1.1.0=0, cLApDot11IfSlotId.0=0,
1.3.6.1.4.1.9.9.513.1.1.1.1.5.32.76.158.234.79.176=RT13-Office-AP2, cLApName.32.76.158.234.79.176=RT13-Office-AP2,
1.3.6.1.4.1.9.9.599.1.3.2.1.2.0=1, cldcClientByIpAddressType.0=1,
1.3.6.1.4.1.9.9.599.1.3.2.1.3.0=ª<030><001>z, cldcClientByIpAddress.0=ª<030><001>z, 1.3.6.1.4.1.9.9.599.1.3.1.1.27.108.232.92.128.7.162=, cldcClientUsername.108.232.92.128.7.162=, 1.3.6.1.4.1.9.9.599.1.3.1.1.28.108.232.92.128.7.162=JMMurrayRT13, cldcClientSSID.108.232.92.128.7.162=JMMurrayRT13, 1.3.6.1.4.1.9.9.599.1.3.1.1.38.108.232.92.128.7.162=5c7fc4dc/6c:e8:5c:80:07:a2/7418, cldcClientSessionID.108.232.92.128.7.162=5c7fc4dc/6c:e8:5c:80:07:a2/7418, 1.3.6.1.4.1.9.9.599.1.3.1.1.8.108.232.92.128.7.162=20:4C:9E:EA:4F:B0, cldcApMacAddress.108.232.92.128.7.162=20:4C:9E:EA:4F:B0
2019-03-06 08:02:23 Auth.Debug 172.30.1.44 community=2504SNMPLogs, enterprise=1.3.6.1.4.1.9.9.599.0.8, enterprise_mib_name=ciscoLwappDot11ClientSessionTrap, uptime=359392500, agent_ip=172.30.1.44, version=Ver2,
1.3.6.1.4.1.9.9.513.1.2.1.1.1.0=1, cLApDot11IfSlotId.0=1,
1.3.6.1.4.1.9.9.513.1.1.1.1.5.32.76.158.234.79.176=RT13-Office-AP2, cLApName.32.76.158.234.79.176=RT13-Office-AP2,
1.3.6.1.4.1.9.9.599.1.3.2.1.2.0=1, cldcClientByIpAddressType.0=1,
1.3.6.1.4.1.9.9.599.1.3.2.1.3.0=ª<030><001>z, cldcClientByIpAddress.0=ª<030><001>z, 1.3.6.1.4.1.9.9.599.1.3.1.1.27.108.232.92.128.7.162=, cldcClientUsername.108.232.92.128.7.162=, 1.3.6.1.4.1.9.9.599.1.3.1.1.28.108.232.92.128.7.162=JMMurrayRT13, cldcClientSSID.108.232.92.128.7.162=JMMurrayRT13, 1.3.6.1.4.1.9.9.599.1.3.1.1.38.108.232.92.128.7.162=5c7fc4dc/6c:e8:5c:80:07:a2/7418, cldcClientSessionID.108.232.92.128.7.162=5c7fc4dc/6c:e8:5c:80:07:a2/7418, 1.3.6.1.4.1.9.9.599.1.3.1.1.8.108.232.92.128.7.162=20:4C:9E:EA:4F:B0, cldcApMacAddress.108.232.92.128.7.162=20:4C:9E:EA:4F:B0
Correct IP Address below 10.10.10.23
2019-03-06 08:24:09 Auth.Debug 172.30.1.44 community=2504SNMPLogs, enterprise=1.3.6.1.4.1.9.9.599.0.8, enterprise_mib_name=ciscoLwappDot11ClientSessionTrap, uptime=359523100, agent_ip=172.30.1.44, version=Ver2,
1.3.6.1.4.1.9.9.513.1.2.1.1.1.0=1, cLApDot11IfSlotId.0=1,
1.3.6.1.4.1.9.9.513.1.1.1.1.5.32.76.158.234.79.176=RT13-Office-AP2, cLApName.32.76.158.234.79.176=RT13-Office-AP2,
1.3.6.1.4.1.9.9.599.1.3.2.1.2.0=1, cldcClientByIpAddressType.0=1,
1.3.6.1.4.1.9.9.599.1.3.2.1.3.0=<010><010><010><023>, cldcClientByIpAddress.0=<010><010><010><023>, 1.3.6.1.4.1.9.9.599.1.3.1.1.27.160.78.167.3.159.103=, cldcClientUsername.160.78.167.3.159.103=,
1.3.6.1.4.1.9.9.599.1.3.1.1.28.160.78.167.3.159.103=JMMurrayGuest, cldcClientSSID.160.78.167.3.159.103=JMMurrayGuest, 1.3.6.1.4.1.9.9.599.1.3.1.1.38.160.78.167.3.159.103=5c7fc8ab/a0:4e:a7:03:9f:67/7423, cldcClientSessionID.160.78.167.3.159.103=5c7fc8ab/a0:4e:a7:03:9f:67/7423, 1.3.6.1.4.1.9.9.599.1.3.1.1.8.160.78.167.3.159.103=20:4C:9E:EA:4F:B0, cldcApMacAddress.160.78.167.3.159.103=20:4C:9E:EA:4F:B0
2019-03-06 08:38:48 Auth.Debug 172.30.1.44 community=2504SNMPLogs, enterprise=1.3.6.1.4.1.9.9.599.0.8, enterprise_mib_name=ciscoLwappDot11ClientSessionTrap, uptime=359611100, agent_ip=172.30.1.44, version=Ver2, 1.3.6.1.4.1.9.9.513.1.2.1.1.1.0=0, cLApDot11IfSlotId.0=0,
1.3.6.1.4.1.9.9.513.1.1.1.1.5.32.76.158.234.79.176=RT13-Office-AP2, cLApName.32.76.158.234.79.176=RT13-Office-AP2,
1.3.6.1.4.1.9.9.599.1.3.2.1.2.0=1, cldcClientByIpAddressType.0=1,
1.3.6.1.4.1.9.9.599.1.3.2.1.3.0=<010><010><010>c, cldcClientByIpAddress.0=<010><010><010>c, 1.3.6.1.4.1.9.9.599.1.3.1.1.27.212.109.109.96.64.180=, cldcClientUsername.212.109.109.96.64.180=, 1.3.6.1.4.1.9.9.599.1.3.1.1.28.212.109.109.96.64.180=JMMurrayGuest, cldcClientSSID.212.109.109.96.64.180=JMMurrayGuest, 1.3.6.1.4.1.9.9.599.1.3.1.1.38.212.109.109.96.64.180=5c7fcd06/d4:6d:6d:60:40:b4/7433, cldcClientSessionID.212.109.109.96.64.180=5c7fcd06/d4:6d:6d:60:40:b4/7433, 1.3.6.1.4.1.9.9.599.1.3.1.1.8.212.109.109.96.64.180=20:4C:9E:EA:4F:B0, cldcApMacAddress.212.109.109.96.64.180=20:4C:9E:EA:4F:B0