<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Default ISE Syslog format for User-Name attribute? in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/default-ise-syslog-format-for-user-name-attribute/m-p/3417240#M22625</link>
    <description>&lt;P&gt;Cisco have now acknowledged this defect but are refusing to prioritize a fix. We need your help to add your name/company to the defect. Cisco&amp;nbsp;allege we are the&amp;nbsp;only organization&amp;nbsp;impacted.&amp;nbsp;If multiple people are impacted Cisco will provide a fix.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please let Cisco know you are impacted and help us pressure Cisco to provide a fix.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Defect Details&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;CSCvk09565 ISE 2.x onwards RFC 3164 is not being followed completely&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Symptom&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Syslog messages are sent with double slash in the username field.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Characters which are escaped with double slash are ,;{}\&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Conditions&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;ISE 2.x version&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Workaround&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;None&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Further Problem Description&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Below characters are escaped as of now&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;,;{}\&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;No Character should be escaped as per RFC 3164 which ISE follows.&lt;/P&gt;</description>
    <pubDate>Wed, 18 Jul 2018 01:00:05 GMT</pubDate>
    <dc:creator>DB101</dc:creator>
    <dc:date>2018-07-18T01:00:05Z</dc:date>
    <item>
      <title>Default ISE Syslog format for User-Name attribute?</title>
      <link>https://community.cisco.com/t5/network-access-control/default-ise-syslog-format-for-user-name-attribute/m-p/3012046#M22610</link>
      <description>&lt;P&gt;We're working with a partner who consumes syslog output from ISE for identity tracking purposes.&lt;/P&gt;
&lt;P&gt;They are reporting getting unexpected output, but I cannot see that any modifications made by us could be resulting in this. Basically they are saying, and it is easily confirmed by looking at output to rsyslog, that the User-Name attribute is not coming across as they expect it. It is coming across as:&lt;/P&gt;
&lt;P&gt;Jun &amp;nbsp;2 16:25:25 servername&amp;nbsp;CISE_RADIUS_Accounting 0009005642 2 0 2017-06-02 16:25:25.722 -05:00 0471296004 3002 NOTICE Radius-Accounting: RADIUS Accounting watchdog update, ConfigVersionId=18, Device IP Address=10.192.65.11, RequestLatency=2, NetworkDeviceName=wlc, &lt;SPAN style="text-decoration: underline; font-size: 18pt;"&gt;&lt;STRONG&gt;User-Name=ourDomain\\james.watson,&lt;/STRONG&gt;&lt;/SPAN&gt; NAS-IP-Address=10.192.65.11, NAS-Port=4, Framed-IP-Address=10.191.87.202, Class=CACS:4d41c00a019356ee5abd3159:servername/285090051/16636127, Called-Station-ID=TECH, Calling-Station-ID=b8-53-ac-76-06-2d, NAS-Identifier=wlc-1, Acct-Status-Type=Interim-Update, Acct-Delay-Time=0, Acct-Input-Octets=18206328, Acct-Output-Octets=97837917, Acct-Session-Id=5931bd5a/b8:53:ac:76:06:2d/36497162, Acct-Authentic=RADIUS, Acct-Session-Time=6760, Acct-Input-Packets=100572, Acct-Output-Packets=117663, undefined-52=#000#000#000#000, undefined-53=#000#000#000#000, Event-Timestamp=1496438725, NAS-Port-Type=Wireless - IEEE 802.11, Tunnel-Type=(tag=0) VLAN, Tunnel-Medium-Type=(tag=0) 802, Tunnel-Private-Group-ID=(tag=0) 1621,&lt;/P&gt;
&lt;P&gt;They report that the double backslash is causing issues that they don't experience with other ISE customers.&lt;/P&gt;
&lt;P&gt;So first question: Is this the default format for this output or not?&lt;/P&gt;
&lt;P&gt;Second question: We are not currently using identity rewrite. Would it be effective in changing this output to syslog?&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 07:45:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/default-ise-syslog-format-for-user-name-attribute/m-p/3012046#M22610</guid>
      <dc:creator>jameswatson33</dc:creator>
      <dc:date>2019-03-11T07:45:54Z</dc:date>
    </item>
    <item>
      <title>Any additional information I</title>
      <link>https://community.cisco.com/t5/network-access-control/default-ise-syslog-format-for-user-name-attribute/m-p/3012047#M22612</link>
      <description>&lt;P&gt;Any additional information I could provide to make the question more precise?&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jun 2017 18:38:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/default-ise-syslog-format-for-user-name-attribute/m-p/3012047#M22612</guid>
      <dc:creator>jameswatson33</dc:creator>
      <dc:date>2017-06-05T18:38:01Z</dc:date>
    </item>
    <item>
      <title>This seems like a pretty</title>
      <link>https://community.cisco.com/t5/network-access-control/default-ise-syslog-format-for-user-name-attribute/m-p/3012048#M22614</link>
      <description>&lt;P&gt;This seems like a pretty straightforward question. Is it possible I'm posting in the wrong forum? Any suggestions to improve my chances of finding an answer?&lt;/P&gt;</description>
      <pubDate>Tue, 06 Jun 2017 13:58:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/default-ise-syslog-format-for-user-name-attribute/m-p/3012048#M22614</guid>
      <dc:creator>jameswatson33</dc:creator>
      <dc:date>2017-06-06T13:58:09Z</dc:date>
    </item>
    <item>
      <title>Re: Default ISE Syslog format for User-Name attribute?</title>
      <link>https://community.cisco.com/t5/network-access-control/default-ise-syslog-format-for-user-name-attribute/m-p/3189249#M22616</link>
      <description>&lt;P&gt;did you get the problem fixed?&amp;nbsp; I have htis issue also&lt;/P&gt;</description>
      <pubDate>Mon, 25 Sep 2017 18:55:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/default-ise-syslog-format-for-user-name-attribute/m-p/3189249#M22616</guid>
      <dc:creator>kd4fmt</dc:creator>
      <dc:date>2017-09-25T18:55:24Z</dc:date>
    </item>
    <item>
      <title>Re: Default ISE Syslog format for User-Name attribute?</title>
      <link>https://community.cisco.com/t5/network-access-control/default-ise-syslog-format-for-user-name-attribute/m-p/3381021#M22618</link>
      <description>&lt;P&gt;Any luck solving this issue? Appreciate sharing your findings&lt;/P&gt;</description>
      <pubDate>Thu, 10 May 2018 00:20:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/default-ise-syslog-format-for-user-name-attribute/m-p/3381021#M22618</guid>
      <dc:creator>LMCisco</dc:creator>
      <dc:date>2018-05-10T00:20:14Z</dc:date>
    </item>
    <item>
      <title>Re: Default ISE Syslog format for User-Name attribute?</title>
      <link>https://community.cisco.com/t5/network-access-control/default-ise-syslog-format-for-user-name-attribute/m-p/3387369#M22620</link>
      <description>&lt;P&gt;for what its worth;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;this is the standard format for windows domain joined machines when peap is configured to 'use windows logon details'. the double backslash is common in unix-like environments to escape the backslash.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;also, as a note - identity-rewrite does not help here, because it only rewrites the identity sent to AD servers. it does not change the identity as far as ISE see's it.&lt;/P&gt;
&lt;P&gt;so - my understanding is this: if ISE gets a request for "santa@north.pole", you can rewrite it to "easter.bunny@myAD.eggdomain" for your myAD.eggdomain servers to authenticate it. BUT, once authenticated, it will still use "santa@north.pole" for the identity (+ therefore radius syslog messages).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;hth&lt;/P&gt;</description>
      <pubDate>Wed, 23 May 2018 01:18:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/default-ise-syslog-format-for-user-name-attribute/m-p/3387369#M22620</guid>
      <dc:creator>blahblarblah</dc:creator>
      <dc:date>2018-05-23T01:18:54Z</dc:date>
    </item>
    <item>
      <title>Re: Default ISE Syslog format for User-Name attribute?</title>
      <link>https://community.cisco.com/t5/network-access-control/default-ise-syslog-format-for-user-name-attribute/m-p/3387913#M22623</link>
      <description>&lt;P&gt;We are running ISE 2.2 and we needed to collect username info in our palo alto live logs. The following link provides you&amp;nbsp;information about this and I think it could probably help you.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Integration-Articles/Integrating-Cisco-ISE-Guest-Authentication-with-PAN-OS/ta-p/98295" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Integration-Articles/Integrating-Cisco-ISE-Guest-Authentication-with-PAN-OS/ta-p/98295&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 23 May 2018 19:14:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/default-ise-syslog-format-for-user-name-attribute/m-p/3387913#M22623</guid>
      <dc:creator>ajc</dc:creator>
      <dc:date>2018-05-23T19:14:38Z</dc:date>
    </item>
    <item>
      <title>Re: Default ISE Syslog format for User-Name attribute?</title>
      <link>https://community.cisco.com/t5/network-access-control/default-ise-syslog-format-for-user-name-attribute/m-p/3417240#M22625</link>
      <description>&lt;P&gt;Cisco have now acknowledged this defect but are refusing to prioritize a fix. We need your help to add your name/company to the defect. Cisco&amp;nbsp;allege we are the&amp;nbsp;only organization&amp;nbsp;impacted.&amp;nbsp;If multiple people are impacted Cisco will provide a fix.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please let Cisco know you are impacted and help us pressure Cisco to provide a fix.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Defect Details&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;CSCvk09565 ISE 2.x onwards RFC 3164 is not being followed completely&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Symptom&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Syslog messages are sent with double slash in the username field.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Characters which are escaped with double slash are ,;{}\&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Conditions&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;ISE 2.x version&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Workaround&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;None&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Further Problem Description&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Below characters are escaped as of now&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;,;{}\&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;No Character should be escaped as per RFC 3164 which ISE follows.&lt;/P&gt;</description>
      <pubDate>Wed, 18 Jul 2018 01:00:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/default-ise-syslog-format-for-user-name-attribute/m-p/3417240#M22625</guid>
      <dc:creator>DB101</dc:creator>
      <dc:date>2018-07-18T01:00:05Z</dc:date>
    </item>
    <item>
      <title>Re: Default ISE Syslog format for User-Name attribute?</title>
      <link>https://community.cisco.com/t5/network-access-control/default-ise-syslog-format-for-user-name-attribute/m-p/3675154#M22626</link>
      <description>&lt;P&gt;logged the case and attached to the bug. cheers.&lt;/P&gt;</description>
      <pubDate>Thu, 26 Jul 2018 08:40:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/default-ise-syslog-format-for-user-name-attribute/m-p/3675154#M22626</guid>
      <dc:creator>blahblarblah</dc:creator>
      <dc:date>2018-07-26T08:40:27Z</dc:date>
    </item>
    <item>
      <title>Re: Default ISE Syslog format for User-Name attribute?</title>
      <link>https://community.cisco.com/t5/network-access-control/default-ise-syslog-format-for-user-name-attribute/m-p/3675864#M22627</link>
      <description>&lt;P&gt;No good news yet. Cisco have not made a commitment to fix this defect.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Still working on it.&lt;/P&gt;</description>
      <pubDate>Thu, 26 Jul 2018 22:29:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/default-ise-syslog-format-for-user-name-attribute/m-p/3675864#M22627</guid>
      <dc:creator>DB101</dc:creator>
      <dc:date>2018-07-26T22:29:26Z</dc:date>
    </item>
    <item>
      <title>Re: Default ISE Syslog format for User-Name attribute?</title>
      <link>https://community.cisco.com/t5/network-access-control/default-ise-syslog-format-for-user-name-attribute/m-p/3685431#M22628</link>
      <description>&lt;P&gt;Defect updated from 'enhancement' to severity 3. Cisco has advised us they are working on a fix.&lt;/P&gt;</description>
      <pubDate>Fri, 10 Aug 2018 00:14:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/default-ise-syslog-format-for-user-name-attribute/m-p/3685431#M22628</guid>
      <dc:creator>DB101</dc:creator>
      <dc:date>2018-08-10T00:14:59Z</dc:date>
    </item>
    <item>
      <title>Re: Default ISE Syslog format for User-Name attribute?</title>
      <link>https://community.cisco.com/t5/network-access-control/default-ise-syslog-format-for-user-name-attribute/m-p/3720713#M22629</link>
      <description>FYI, we received a custom patch and are yet to test it. The fix will be added to future versions.</description>
      <pubDate>Mon, 08 Oct 2018 00:14:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/default-ise-syslog-format-for-user-name-attribute/m-p/3720713#M22629</guid>
      <dc:creator>DB101</dc:creator>
      <dc:date>2018-10-08T00:14:07Z</dc:date>
    </item>
    <item>
      <title>Re: Default ISE Syslog format for User-Name attribute?</title>
      <link>https://community.cisco.com/t5/network-access-control/default-ise-syslog-format-for-user-name-attribute/m-p/3720759#M22630</link>
      <description>&lt;P&gt;I suggest please reach out to your account team to get this defect prioritized and they can update you once the fix is available.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 08 Oct 2018 06:03:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/default-ise-syslog-format-for-user-name-attribute/m-p/3720759#M22630</guid>
      <dc:creator>Nidhi</dc:creator>
      <dc:date>2018-10-08T06:03:39Z</dc:date>
    </item>
    <item>
      <title>Re: Default ISE Syslog format for User-Name attribute?</title>
      <link>https://community.cisco.com/t5/network-access-control/default-ise-syslog-format-for-user-name-attribute/m-p/3751072#M22631</link>
      <description>&lt;P&gt;We received a patch from Cisco that addresses this issue and results in a single backslash. Suggest you contact Cisco and request the patch. I believe it will be incorporated in a future release.&lt;/P&gt;</description>
      <pubDate>Wed, 21 Nov 2018 22:26:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/default-ise-syslog-format-for-user-name-attribute/m-p/3751072#M22631</guid>
      <dc:creator>DB101</dc:creator>
      <dc:date>2018-11-21T22:26:26Z</dc:date>
    </item>
    <item>
      <title>Re: Default ISE Syslog format for User-Name attribute?</title>
      <link>https://community.cisco.com/t5/network-access-control/default-ise-syslog-format-for-user-name-attribute/m-p/3752068#M22632</link>
      <description>&lt;P&gt;Hi, can you share me the patch please. I really need it to fix my case. Thanks very much,Quang!&lt;/P&gt;</description>
      <pubDate>Sat, 24 Nov 2018 03:27:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/default-ise-syslog-format-for-user-name-attribute/m-p/3752068#M22632</guid>
      <dc:creator>quangle1993</dc:creator>
      <dc:date>2018-11-24T03:27:49Z</dc:date>
    </item>
    <item>
      <title>Re: Default ISE Syslog format for User-Name attribute?</title>
      <link>https://community.cisco.com/t5/network-access-control/default-ise-syslog-format-for-user-name-attribute/m-p/3752069#M22633</link>
      <description>&lt;P&gt;Hi, can you share me the patch please. I really need it to fix my case. Thanks very much,Quang!&lt;/P&gt;</description>
      <pubDate>Sat, 24 Nov 2018 03:27:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/default-ise-syslog-format-for-user-name-attribute/m-p/3752069#M22633</guid>
      <dc:creator>quangle1993</dc:creator>
      <dc:date>2018-11-24T03:27:59Z</dc:date>
    </item>
    <item>
      <title>Re: Default ISE Syslog format for User-Name attribute?</title>
      <link>https://community.cisco.com/t5/network-access-control/default-ise-syslog-format-for-user-name-attribute/m-p/3752071#M22634</link>
      <description>Work through the tac&lt;BR /&gt;</description>
      <pubDate>Sat, 24 Nov 2018 03:54:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/default-ise-syslog-format-for-user-name-attribute/m-p/3752071#M22634</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2018-11-24T03:54:29Z</dc:date>
    </item>
    <item>
      <title>Re: Default ISE Syslog format for User-Name attribute?</title>
      <link>https://community.cisco.com/t5/network-access-control/default-ise-syslog-format-for-user-name-attribute/m-p/3752076#M22635</link>
      <description>&lt;P&gt;Me too.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We are facing to the same problem with \\ (2 back slash).&lt;/P&gt;
&lt;P&gt;Could anyone share the patch or how to fix it?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Minh&lt;/P&gt;</description>
      <pubDate>Sat, 24 Nov 2018 05:21:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/default-ise-syslog-format-for-user-name-attribute/m-p/3752076#M22635</guid>
      <dc:creator>tminh</dc:creator>
      <dc:date>2018-11-24T05:21:06Z</dc:date>
    </item>
    <item>
      <title>Re: Default ISE Syslog format for User-Name attribute?</title>
      <link>https://community.cisco.com/t5/network-access-control/default-ise-syslog-format-for-user-name-attribute/m-p/3752150#M22636</link>
      <description>Patches aren’t shared here please work through the tac &lt;BR /&gt;</description>
      <pubDate>Sat, 24 Nov 2018 12:26:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/default-ise-syslog-format-for-user-name-attribute/m-p/3752150#M22636</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2018-11-24T12:26:04Z</dc:date>
    </item>
  </channel>
</rss>

