<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic External Syslog Sizing ISE in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/external-syslog-sizing-ise/m-p/3813690#M484601</link>
    <description>&lt;P&gt;Hello&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Need help in finding the size of a syslog message in case of device Admin function for both Tacacs and radius when syslog are sent to external logging servers&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 04 Mar 2019 17:13:45 GMT</pubDate>
    <dc:creator>hsangral</dc:creator>
    <dc:date>2019-03-04T17:13:45Z</dc:date>
    <item>
      <title>External Syslog Sizing ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/external-syslog-sizing-ise/m-p/3813690#M484601</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Need help in finding the size of a syslog message in case of device Admin function for both Tacacs and radius when syslog are sent to external logging servers&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 04 Mar 2019 17:13:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/external-syslog-sizing-ise/m-p/3813690#M484601</guid>
      <dc:creator>hsangral</dc:creator>
      <dc:date>2019-03-04T17:13:45Z</dc:date>
    </item>
    <item>
      <title>Re: External Syslog Sizing ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/external-syslog-sizing-ise/m-p/3813908#M484602</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Let me know if this is what you looking for??&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Number of sessions per day:&amp;nbsp; 4&lt;/P&gt;
&lt;P&gt;Number of commands:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10&lt;/P&gt;
&lt;P&gt;Message Size /session (KB) = 5kB + Number of commands/session *3kB&lt;/P&gt;
&lt;P&gt;Automated access(single script) log size calculation =&amp;nbsp; n Number of devices * 4 Sessions * Message size&lt;/P&gt;
&lt;P&gt;E.g. : Log Size for 30k Network devices = 4GB/day&lt;/P&gt;</description>
      <pubDate>Mon, 04 Mar 2019 23:50:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/external-syslog-sizing-ise/m-p/3813908#M484602</guid>
      <dc:creator>mnagired</dc:creator>
      <dc:date>2019-03-04T23:50:02Z</dc:date>
    </item>
    <item>
      <title>Re: External Syslog Sizing ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/external-syslog-sizing-ise/m-p/3813927#M484604</link>
      <description>What mnagired posted are the published guidelines for log storage.  If the deployment already exists then there is an easy method of confirming space. This ISE GUI page will show you what's currently being stored for the past 30 days.  &lt;BR /&gt;https://&amp;lt;ise ip&amp;gt;/admin/#administration/administration_system/administration_system_backup/data_purging&lt;BR /&gt;&lt;BR /&gt;What actually gets sent to the external syslog server, is everything you see in the authentication details log.  No way to change the data that is being sent, only selecting the categories.  The message size differs a little bit based on various components of your config because things like network device groups, AD details (number of domains found) etc are different for every deployment.</description>
      <pubDate>Tue, 05 Mar 2019 00:49:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/external-syslog-sizing-ise/m-p/3813927#M484604</guid>
      <dc:creator>Damien Miller</dc:creator>
      <dc:date>2019-03-05T00:49:48Z</dc:date>
    </item>
    <item>
      <title>Re: External Syslog Sizing ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/external-syslog-sizing-ise/m-p/3814645#M484606</link>
      <description>&lt;P&gt;To get an idea of the actual UDP packet, just enable any external syslog logging host (doesn't have to be a valid IP) and then run a tcpdump on ISE PAN node.&amp;nbsp; You will be able to capture the UDP data.&lt;/P&gt;</description>
      <pubDate>Wed, 06 Mar 2019 02:31:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/external-syslog-sizing-ise/m-p/3814645#M484606</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2019-03-06T02:31:17Z</dc:date>
    </item>
  </channel>
</rss>

