Are you using an MSE, and if so what version? If not, you will need that for any "endpoint" mapping to occur, otherwise it's just AP placements and heatmaps essentially, no endpoint tracking.
If you do have an MSE, what type of licensing do you have? The base license will allow you to track clients, rogue clients, rogue aps, and rfid. If you are wanting to track things detected by the IPS, such as a "Broadcast Probe Request Flood", you would need wIPS licensing, and a proper wIPS profile pushed to your APs to then operate in ELM or MM fashion.
Transferring Crash file from standby: Login to the Active WLC in HA.
From CLI: (Cisco Controller) >transfer upload datatype crash (Cisco
Controller) >transfer upload filename (Cisco
Controller) >transfer upload mode tftp (Cisco Controller) >transfer
This is the start of a display filter cross reference between Wireshark
and OmniPeek. The 1st installment is a table of advanced filters. More
filters will be added as time allows. It is a living doc, so check back
for changes every so often Please feel f...