<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE SYSLOG message reduction in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-syslog-message-reduction/m-p/3479442#M523689</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;On my phone, I can see you are mainly interest in &lt;/P&gt;&lt;UL&gt;&lt;LI&gt;passed authentications&lt;/LI&gt;&lt;LI&gt;failed attempts&lt;/LI&gt;&lt;LI&gt;RADIUS accounting&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thus, add your targets to those only and remove from the others. You would be getting acct interim updates as they are in the same category as acct start.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 14 Jul 2017 13:55:35 GMT</pubDate>
    <dc:creator>hslai</dc:creator>
    <dc:date>2017-07-14T13:55:35Z</dc:date>
    <item>
      <title>ISE SYSLOG message reduction</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-syslog-message-reduction/m-p/3479439#M523686</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have enabled SYSLOG to two remote targets and I see a lot &lt;STRONG&gt;more messages being sent than I'd like to see.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Let's just say the receiving syslog server vendor likes to charge by data volume ... you know who I mean &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My intention is to try reduce the amount of chaff that is being sent. The image below is a bit high res - but it shows the typical messages I am interested in (highlighted) and the rest is not interesting to me. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Cisco ISE SYSLOG decoded in Wireshark.png" class="image-1 jive-image" src="/legacyfs/online/fusion/109139_Cisco ISE SYSLOG decoded in Wireshark.png" style="width: 620px; height: 339px;" /&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG class="jive-image image-3" src="https://community.cisco.com/legacyfs/online/fusion/109141_pastedImage_4.png" style="max-height: 900px; max-width: 1200px;" /&gt;&lt;/P&gt;&lt;P&gt;I am also a bit unsure what the "Local Log Level" enable/disable means ... local to &lt;EM&gt;what&lt;/EM&gt;?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can't seem to find the right settings in ISE to fine tune the messages.&amp;nbsp; I thought it may be under the Debug Log Configuration, because some of the SYSLOGs that I do NOT want to see, appear to me as being as a result of debugging enabled.&amp;nbsp;&amp;nbsp; But I have not touched the Debug Level Configurations - not sure how they relate to the actual SYSLOGs that I see.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG class="jive-image image-2" src="https://community.cisco.com/legacyfs/online/fusion/109140_pastedImage_1.png" style="max-height: 900px; max-width: 1200px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Anyone got some advice for me please?&lt;/STRONG&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 14 Jul 2017 05:29:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-syslog-message-reduction/m-p/3479439#M523686</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2017-07-14T05:29:41Z</dc:date>
    </item>
    <item>
      <title>Re: ISE SYSLOG message reduction</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-syslog-message-reduction/m-p/3479440#M523687</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Arnie,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;One way to reduce the logs will be to change the log levels of categories which are not of importance , to WARN, ERROR or FATAL .&lt;/P&gt;&lt;P&gt;INFO level generates logs for every transaction , config change , config consumption , which normally you would not care much if everything works well.&lt;/P&gt;&lt;P&gt;Other way could be&amp;nbsp; to remove the target syslog server from unwanted categories.&lt;/P&gt;&lt;P&gt;At present as far as I know , we cannot disable any logging category .&lt;/P&gt;&lt;P&gt;but you can raise this request with the PM team .&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Nidhi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;DIV class="BubbleStyle_MessageContainer"&gt;&lt;P&gt;&lt;/P&gt;&lt;/DIV&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 14 Jul 2017 08:04:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-syslog-message-reduction/m-p/3479440#M523687</guid>
      <dc:creator>Nidhi</dc:creator>
      <dc:date>2017-07-14T08:04:18Z</dc:date>
    </item>
    <item>
      <title>Re: ISE SYSLOG message reduction</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-syslog-message-reduction/m-p/3479441#M523688</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Adding to Nidhi's...&lt;/P&gt;&lt;P&gt;ISE syslog has many categories so please add your targets to the ones you are interested in. Your screenshots are not high enough resolution for me to tell.&amp;nbsp; Each syslog entry has the category in it; e.g.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;Aug 6 10:25:01 HOST/X.X.X.X CISE_&lt;STRONG&gt;Posture_and_Client_Provisioning_Audit&lt;/STRONG&gt; 0000062241 4 0 2012-08-06 10:25:01.177 +01:00 0005085661 87000 NOTICE Posture: ...&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The local logging refers to ISE local store logs, as shown below:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE __default_attr="plain" __jive_macro_name="code" class="jive_text_macro jive_macro_code _jivemacro_uid_15000330738076219" jivemacro_uid="_15000330738076219"&gt;
&lt;P&gt;myISE/admin# show logging application | inc local&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 5914 Jul 14 2017 04:32:10&amp;nbsp; appserver/localhost.2017-07-14.log&lt;/P&gt;
&lt;P&gt;--&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 251557 Jul 14 2017 11:42:41&amp;nbsp; localStore/iseLocalStore.log&lt;/P&gt;


&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The local store logs are under localStore so only the 2nd entry is.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The ISE debug configuration is for local debug only and does not go to syslog.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 14 Jul 2017 11:45:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-syslog-message-reduction/m-p/3479441#M523688</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2017-07-14T11:45:49Z</dc:date>
    </item>
    <item>
      <title>Re: ISE SYSLOG message reduction</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-syslog-message-reduction/m-p/3479442#M523689</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;On my phone, I can see you are mainly interest in &lt;/P&gt;&lt;UL&gt;&lt;LI&gt;passed authentications&lt;/LI&gt;&lt;LI&gt;failed attempts&lt;/LI&gt;&lt;LI&gt;RADIUS accounting&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thus, add your targets to those only and remove from the others. You would be getting acct interim updates as they are in the same category as acct start.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 14 Jul 2017 13:55:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-syslog-message-reduction/m-p/3479442#M523689</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2017-07-14T13:55:35Z</dc:date>
    </item>
    <item>
      <title>Re: ISE SYSLOG message reduction</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-syslog-message-reduction/m-p/3479443#M523690</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You need to click on the images - the browser should enlarge them.&lt;/P&gt;&lt;P&gt;In the case below I only enabled Category Passed Authentications.&amp;nbsp; What I am asking about is how to get rid of all the stuff there that I don't want to see, e.g. the internal ISE DeviceType stuff, what Profile was selected and the fact that Dynamic Authorization succeeded etc.&amp;nbsp; In my view those are Severity level INFO and not NOTICE.&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-1 jive-image" src="https://community.cisco.com/legacyfs/online/fusion/109155_pastedImage_0.png" style="max-height: 900px; max-width: 1200px;" /&gt;&lt;/P&gt;&lt;P&gt;If I understand Nidhi's comments, one cannot fine tune the sub-categories within the Categories ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would consider setting my Logging Targets' Facility Code to LOCAL5 (NOTICE) and then I would not have to log all the INFO and DEBUG stuff.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 16 Jul 2017 22:47:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-syslog-message-reduction/m-p/3479443#M523690</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2017-07-16T22:47:46Z</dc:date>
    </item>
    <item>
      <title>Re: ISE SYSLOG message reduction</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-syslog-message-reduction/m-p/3479444#M523691</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You might be thinking about the Message Classes under each of the message categories as in the Message Catalog page. Then, you are correct that a logging target can only receive a category as a whole but not selectively among the message classes.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;All the available parent and child categories are shown in the logging categories page. For example, the parent category "AAA Audit" has three categories -- AAA Audit, Failed Attempts, and Passed Authentications.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On my ISE, certain logging categories permit logging level changes but that applies to all the targets receiving the events from the particular category. There is no logging level setting for a remote logging target. I guess you may filter on logging levels on your syslog server.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 17 Jul 2017 00:11:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-syslog-message-reduction/m-p/3479444#M523691</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2017-07-17T00:11:57Z</dc:date>
    </item>
  </channel>
</rss>

