Hi Mel, I used the debug user-id command for syslog strings given as example in below and it it worked fine. How to Configure a Custom Syslog Sender and Test User Mappings > debug user-id test user-id-syslog-parse field-identifier event-string "User Authentication Successful:" username-prefix "username=" username-delimiter "\s" address-prefix "IP=" address-delimiter "\s" log-string "2013-03-20 12:56:53 local4.notice Aruba-Local3 authmgr[1568]: <522008> <NOTI> <Aruba-Local3 10.200.10.10> User Authentication Successful: username=ilija MAC=78:f5:fd:dd:ff:90 IP=10.200.27.67" Field parsing successful, Username 'ilija', Address '10.200.27.67' Which syslog server you are using? Can it convert snmp trap to syslog format? I did some research and found this link and I hope it is helpful in fixing the problem. Use Syslog Receiver to Integrate with Cisco Wireless Controller Series Please check the above two links and if still no success, then you can open a case with support. Thanks
... View more