<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE 2.4 Patch 6 Filtering of Live logs not possible in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-2-4-patch-6-filtering-of-live-logs-not-possible/m-p/3836813#M473951</link>
    <description>It doesn´t matter which way you are filtering the Data in Live Logs. It´s not working with quick filter. I want to filter for a specific policy set, like you see in the attached screenshot. On old ISE Version (2.3 Patch 5) i have filtered for a specific Policy set, and the result was that i saw all passed, failed Authentication and the Sessions. In New Version (2.4 Patch 6) I only see passed and failed Authentications without the sessions.</description>
    <pubDate>Thu, 11 Apr 2019 13:41:31 GMT</pubDate>
    <dc:creator>thomas.pflaum</dc:creator>
    <dc:date>2019-04-11T13:41:31Z</dc:date>
    <item>
      <title>ISE 2.4 Patch 6 Filtering of Live logs not possible</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-4-patch-6-filtering-of-live-logs-not-possible/m-p/3836614#M473936</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;i have upgraded ISE form 2.3 to Version 2.4 Patch 6. I have used self created Filters for Live Logs, you are lost in logs if you are not able to use it....&lt;/P&gt;&lt;P&gt;Now in Version 2.4 Patch 6 you are able to use the self created filters, but the result of filtering is different than before. I only see Passed/Failed Authentications no Sessions any more. The Filtering is configured to get live logs only for one specific Authenication Policy.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The behavior is the same, if i´m filtering for a specific Authenication Polcy in the column in the Live Logs.&lt;/P&gt;&lt;P&gt;If you filter based on the Identity in Live Logs, i see Passed/Failed Authentications and Sessions.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does anybody have this same problem, or i´m doing something wrong?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Thomas&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 11 Apr 2019 08:18:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-4-patch-6-filtering-of-live-logs-not-possible/m-p/3836614#M473936</guid>
      <dc:creator>thomas.pflaum</dc:creator>
      <dc:date>2019-04-11T08:18:33Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.4 Patch 6 Filtering of Live logs not possible</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-4-patch-6-filtering-of-live-logs-not-possible/m-p/3836804#M473949</link>
      <description>&lt;P&gt;I only use the quick filter, but I just tried advanced filter with Authorization Profile and I get all record types.&amp;nbsp; How exactly are you doing the filtering?&amp;nbsp; I hide my authentication and authorization policy columns and only do filtering on authorization profile column because every result in my ISE deployments has a unique name using a well structured naming convention.&lt;/P&gt;</description>
      <pubDate>Thu, 11 Apr 2019 13:25:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-4-patch-6-filtering-of-live-logs-not-possible/m-p/3836804#M473949</guid>
      <dc:creator>paul</dc:creator>
      <dc:date>2019-04-11T13:25:09Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.4 Patch 6 Filtering of Live logs not possible</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-4-patch-6-filtering-of-live-logs-not-possible/m-p/3836813#M473951</link>
      <description>It doesn´t matter which way you are filtering the Data in Live Logs. It´s not working with quick filter. I want to filter for a specific policy set, like you see in the attached screenshot. On old ISE Version (2.3 Patch 5) i have filtered for a specific Policy set, and the result was that i saw all passed, failed Authentication and the Sessions. In New Version (2.4 Patch 6) I only see passed and failed Authentications without the sessions.</description>
      <pubDate>Thu, 11 Apr 2019 13:41:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-4-patch-6-filtering-of-live-logs-not-possible/m-p/3836813#M473951</guid>
      <dc:creator>thomas.pflaum</dc:creator>
      <dc:date>2019-04-11T13:41:31Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.4 Patch 6 Filtering of Live logs not possible</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-4-patch-6-filtering-of-live-logs-not-possible/m-p/3836937#M473953</link>
      <description>&lt;P&gt;You shouldn't be getting session information when filtering in RADIUS live logs.&amp;nbsp; If you were getting it in the past, it was most likely a defect that we fixed in 2.4.&amp;nbsp; To view session information, click the Live Sessions tab.&amp;nbsp; You can then filter from there.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;-Tim&lt;/P&gt;</description>
      <pubDate>Thu, 11 Apr 2019 15:47:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-4-patch-6-filtering-of-live-logs-not-possible/m-p/3836937#M473953</guid>
      <dc:creator>Timothy Abbott</dc:creator>
      <dc:date>2019-04-11T15:47:40Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.4 Patch 6 Filtering of Live logs not possible</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-4-patch-6-filtering-of-live-logs-not-possible/m-p/3837398#M473956</link>
      <description>&lt;P&gt;Hey Tim,&lt;/P&gt;&lt;P&gt;filtering inlcuding all Status (session, auth failed, auth passed) works in Version 2.4 in all column´s of the livelogs except of Authentication Policy and Authorization Policy.&lt;/P&gt;&lt;P&gt;I have tried to filter for Authentication Policy and Authorization Policy in Live session tab without success.&lt;/P&gt;&lt;P&gt;This sounds for me like a bug, not a feature.&lt;/P&gt;&lt;P&gt;BR&lt;/P&gt;&lt;P&gt;Thomas&lt;/P&gt;</description>
      <pubDate>Fri, 12 Apr 2019 06:04:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-4-patch-6-filtering-of-live-logs-not-possible/m-p/3837398#M473956</guid>
      <dc:creator>thomas.pflaum</dc:creator>
      <dc:date>2019-04-12T06:04:20Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.4 Patch 6 Filtering of Live logs not possible</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-4-patch-6-filtering-of-live-logs-not-possible/m-p/3837532#M473957</link>
      <description>&lt;P&gt;Thomas,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;That is funny.&amp;nbsp; Those are the two columns I hide and have all my customers hide because for the most part you don't need to use those columns if you have a good naming convention on your Authorization Profiles.&amp;nbsp; I just unhid them and you are correct blue session records aren't shown when you filter using either of those two columns.&amp;nbsp; Definitely a bug in my opinion.&amp;nbsp; Open a TAC case and have them get a bug filed.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Apr 2019 10:58:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-4-patch-6-filtering-of-live-logs-not-possible/m-p/3837532#M473957</guid>
      <dc:creator>paul</dc:creator>
      <dc:date>2019-04-12T10:58:09Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.4 Patch 6 Filtering of Live logs not possible</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-4-patch-6-filtering-of-live-logs-not-possible/m-p/3837557#M473959</link>
      <description>&lt;P&gt;Paul,&lt;/P&gt;&lt;P&gt;Thank you for you feedback. I already open a Case at Cisco.&lt;/P&gt;&lt;P&gt;BR&lt;/P&gt;&lt;P&gt;Thomas&lt;/P&gt;</description>
      <pubDate>Fri, 12 Apr 2019 11:54:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-4-patch-6-filtering-of-live-logs-not-possible/m-p/3837557#M473959</guid>
      <dc:creator>thomas.pflaum</dc:creator>
      <dc:date>2019-04-12T11:54:34Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.4 Patch 6 Filtering of Live logs not possible</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-4-patch-6-filtering-of-live-logs-not-possible/m-p/3843742#M473961</link>
      <description>&lt;P&gt;Hello All,&lt;/P&gt;&lt;P&gt;result from opening TAC case:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://urldefense.proofpoint.com/v2/url?u=https-3A__bst.cloudapps.cisco.com_bugsearch_bug_CSCvp19738_-3Freffering-5Fsite-3Ddumpcr&amp;amp;d=DwMGaQ&amp;amp;c=68HcvFK2AZ4RUGlmK9Z3SQ&amp;amp;r=EaNWp5fih3Qh1uXxXc9zmbVAr7nTZQcPOPv--eFlFSo&amp;amp;m=E6tCVNdeZ0IV_ZlaVomV847wDg48z1s-hfbLZGY5ec0&amp;amp;s=NCnnQeGsHsQHVWHxOKiFnXBzCakpzbvzZK3qUtgWpkc&amp;amp;e=" target="_blank" rel="noopener"&gt;https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvp19738/?reffering_site=dumpcr&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So it is &lt;SPAN&gt;definitely&lt;/SPAN&gt; a bug in Version 2.4 Patch 6.&lt;/P&gt;&lt;P&gt;Thanks to all.&lt;/P&gt;&lt;P&gt;BR&lt;/P&gt;&lt;P&gt;Thomas&lt;/P&gt;</description>
      <pubDate>Wed, 24 Apr 2019 06:16:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-4-patch-6-filtering-of-live-logs-not-possible/m-p/3843742#M473961</guid>
      <dc:creator>thomas.pflaum</dc:creator>
      <dc:date>2019-04-24T06:16:49Z</dc:date>
    </item>
  </channel>
</rss>

