Did you figure this out? I am sending syslogs from each Aerohive AP to a PA User-ID Agent on a server. They are then sent to my PA FW. I had to reformat the syslog filter to : type Field event string : ah_auth Username Prefix : username Username Delimiter: \s address prefix: ip Address Delimiter: \s Address per log: 1 I came to this post because I am researching how to consolidate the logs a bit. I have more AH APs than the User-ID agent allows. I will look into Kiwi or a second User-ID agent.
... View more