<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: CEF format for ISE logs in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cef-format-for-ise-logs/m-p/3520841#M518412</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;i have our SME @john eppich working on posting a guide for ISE and arc sight, please standby&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 24 Jan 2018 18:03:29 GMT</pubDate>
    <dc:creator>Jason Kunst</dc:creator>
    <dc:date>2018-01-24T18:03:29Z</dc:date>
    <item>
      <title>CEF format for ISE logs</title>
      <link>https://community.cisco.com/t5/network-access-control/cef-format-for-ise-logs/m-p/3520835#M518406</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;I'm receiving this question from the customer. ArcSight is the SIEM they have to collect everything related to security.&lt;/P&gt;&lt;UL style="list-style-type: disc;"&gt;&lt;LI&gt;&lt;STRONG&gt;&lt;SPAN lang="EN-US" style="color: #1f497d;"&gt;Log export in CEF format from ISE&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P style="margin: 0 0 0 72pt; font-size: 11pt; font-family: Calibri, sans-serif; color: #000000; text-indent: -18pt;"&gt;&lt;SPAN lang="EN-US" style="font-family: 'Courier New'; color: #1f497d;"&gt;o&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;SPAN lang="EN-US" style="color: #1f497d;"&gt;We would like to collect ISE logging on the same central syslog server mentioned above. If ISE isn’t capable of exporting logs in this format:&lt;/SPAN&gt;&lt;/P&gt;&lt;UL style="list-style-type: disc;"&gt;&lt;LI&gt;&lt;SPAN lang="EN-US" style="color: #1f497d;"&gt;Is it a feature on the roadmap? ISE 2.3 is not a long term support release, so we may need to upgrade it in the near future.&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN lang="EN-US" style="color: #1f497d;"&gt;Can you provide some custom parser in order to analyze those logs?&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks a lot,&lt;/P&gt;&lt;P&gt;Marco&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Jan 2018 08:44:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cef-format-for-ise-logs/m-p/3520835#M518406</guid>
      <dc:creator>mstangal</dc:creator>
      <dc:date>2018-01-24T08:44:33Z</dc:date>
    </item>
    <item>
      <title>Re: CEF format for ISE logs</title>
      <link>https://community.cisco.com/t5/network-access-control/cef-format-for-ise-logs/m-p/3520836#M518407</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am pretty sure that we cannot send in CEF format&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Great information here for logging settings, remote collection points and more&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;https://www.cisco.com/c/en/us/td/docs/security/ise/2-3/admin_guide/b_ise_admin_guide_23/b_ise_admin_guide_23_chapter_01011.html?bookSearch=true&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What other logging siem have done is write their own collector to consume our syslog&lt;/P&gt;&lt;P&gt;Example&lt;/P&gt;&lt;P&gt; http://docs.splunk.com/Documentation/AddOns/released/CiscoISE/ConfigureCiscoISEsystemlogging&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would suggest reaching out to ise product management through sales channels for a feature request&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Jan 2018 13:43:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cef-format-for-ise-logs/m-p/3520836#M518407</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2018-01-24T13:43:59Z</dc:date>
    </item>
    <item>
      <title>Re: CEF format for ISE logs</title>
      <link>https://community.cisco.com/t5/network-access-control/cef-format-for-ise-logs/m-p/3520837#M518408</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jason,&lt;/P&gt;&lt;P&gt;thanks a lot for your answer. Can you elaborate a little bit more what you are thinking about and what I could suggest to the customer? I have shared the document in attach with the customer, how this is different from the Spluk implementation?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I’m not aware of the CEF format so I don’t know why the customer is asking for that and which would be the advantages on supporting it.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Jan 2018 13:57:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cef-format-for-ise-logs/m-p/3520837#M518408</guid>
      <dc:creator>mstangal</dc:creator>
      <dc:date>2018-01-24T13:57:11Z</dc:date>
    </item>
    <item>
      <title>Re: CEF format for ISE logs</title>
      <link>https://community.cisco.com/t5/network-access-control/cef-format-for-ise-logs/m-p/3520838#M518409</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Would recommend that the customer look into asking their siem vendor about a custom solution like splunk has done with their ISE app or Maybe a partner has a custom solution for parsing the logs&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can reach out via sales team to ISE product management and ask for a feature request as well to see if we will ever do CEF&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Jan 2018 14:13:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cef-format-for-ise-logs/m-p/3520838#M518409</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2018-01-24T14:13:24Z</dc:date>
    </item>
    <item>
      <title>Re: CEF format for ISE logs</title>
      <link>https://community.cisco.com/t5/network-access-control/cef-format-for-ise-logs/m-p/3520839#M518410</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jason,&lt;/P&gt;&lt;P&gt;do you have a contact to get in touch with BU?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks a lot,&lt;/P&gt;&lt;P&gt;Marco&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Jan 2018 14:16:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cef-format-for-ise-logs/m-p/3520839#M518410</guid>
      <dc:creator>mstangal</dc:creator>
      <dc:date>2018-01-24T14:16:26Z</dc:date>
    </item>
    <item>
      <title>Re: CEF format for ISE logs</title>
      <link>https://community.cisco.com/t5/network-access-control/cef-format-for-ise-logs/m-p/3520840#M518411</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;As you already provided, ArcSight has ability to consume ISE syslog so not clear on requirement. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If need specific functionality from ArcSight (additional canned reports, queries, etc), then that would be request to 3rd-party vendor.&amp;nbsp; If specific enhancement request for ISE, then that can be communicated to Cisco account team who can then forward to proper internal alias for ISE PM support.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Craig&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Jan 2018 14:29:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cef-format-for-ise-logs/m-p/3520840#M518411</guid>
      <dc:creator>Craig Hyps</dc:creator>
      <dc:date>2018-01-24T14:29:15Z</dc:date>
    </item>
    <item>
      <title>Re: CEF format for ISE logs</title>
      <link>https://community.cisco.com/t5/network-access-control/cef-format-for-ise-logs/m-p/3520841#M518412</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;i have our SME @john eppich working on posting a guide for ISE and arc sight, please standby&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Jan 2018 18:03:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cef-format-for-ise-logs/m-p/3520841#M518412</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2018-01-24T18:03:29Z</dc:date>
    </item>
    <item>
      <title>Re: CEF format for ISE logs</title>
      <link>https://community.cisco.com/t5/network-access-control/cef-format-for-ise-logs/m-p/4701082#M577677</link>
      <description>&lt;P&gt;I have been asked to provide CEF logs from ISE to MS Sentinel.&amp;nbsp; &amp;nbsp;We are using ISE 3.0, am I right in thinking that this is still not available ?&amp;nbsp; &amp;nbsp;If not, is it on the roadmap for future releases ?&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;Clive&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Oct 2022 08:04:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cef-format-for-ise-logs/m-p/4701082#M577677</guid>
      <dc:creator>clive-fulton</dc:creator>
      <dc:date>2022-10-11T08:04:56Z</dc:date>
    </item>
    <item>
      <title>Re: CEF format for ISE logs</title>
      <link>https://community.cisco.com/t5/network-access-control/cef-format-for-ise-logs/m-p/4701523#M577697</link>
      <description>&lt;P&gt;There is currently no capability for ISE to send logs in CEF format and roadmap is not discussed on this public forum. You should be able to stand up a dedicated Linux log collector to collect syslog from ISE and send it to MS Sentinel as per &lt;A href="https://learn.microsoft.com/en-us/azure/sentinel/connect-syslog" target="_blank" rel="noopener"&gt;this Microsoft document&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;You can request enhancements via &lt;A href="https://cs.co/ise-wish" target="_blank" rel="noopener"&gt;https://cs.co/ise-wish&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Oct 2022 21:27:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cef-format-for-ise-logs/m-p/4701523#M577697</guid>
      <dc:creator>Greg Gibbs</dc:creator>
      <dc:date>2022-10-11T21:27:25Z</dc:date>
    </item>
  </channel>
</rss>

