<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Forwarding ISE Authentication Logging to Splunk in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/forwarding-ise-authentication-logging-to-splunk/m-p/4109277#M561411</link>
    <description>Make sure you update the logging categories in ISE to add the new target (splunk).  This should assist you in your journey: &lt;A href="http://www.network-node.com/blog/2017/7/2/integrating-ise-with-splunk" target="_blank"&gt;http://www.network-node.com/blog/2017/7/2/integrating-ise-with-splunk&lt;/A&gt;&lt;BR /&gt;HTH!</description>
    <pubDate>Thu, 25 Jun 2020 12:41:49 GMT</pubDate>
    <dc:creator>Mike.Cifelli</dc:creator>
    <dc:date>2020-06-25T12:41:49Z</dc:date>
    <item>
      <title>Forwarding ISE Authentication Logging to Splunk</title>
      <link>https://community.cisco.com/t5/network-access-control/forwarding-ise-authentication-logging-to-splunk/m-p/4109084#M561401</link>
      <description>&lt;P&gt;Hi Guys,&lt;/P&gt;&lt;P&gt;I want to forward Cisco ISE authentication logging to Splunk. The goal is to capture the authentication success from endpoints to ISE.&lt;/P&gt;&lt;P&gt;So far I already configured the Splunk IP and port on Remote Logging Targets and added it on AAA Audit's Targets column. There are logs that forwarded to ISE, but only contains purging messages. Not the authentication messages like I wanted. Below is the example of the log.&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;182&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;Jun&lt;/SPAN&gt; &lt;SPAN class="t"&gt;25&lt;/SPAN&gt; &lt;SPAN class="t"&gt;05:40:27&lt;/SPAN&gt;&amp;nbsp;ISE_Hostname&amp;nbsp;&lt;SPAN class="t"&gt;CISE_MONITORING_DATA_PURGE_AUDIT&lt;/SPAN&gt; &lt;SPAN class="t"&gt;2020-06-25&lt;/SPAN&gt; &lt;SPAN class="t"&gt;04:52:10.062&lt;/SPAN&gt;&lt;SPAN&gt; +&lt;/SPAN&gt;&lt;SPAN class="t"&gt;0700&lt;/SPAN&gt; &lt;SPAN class="t"&gt;60198&lt;/SPAN&gt; &lt;SPAN class="t"&gt;INFO&lt;/SPAN&gt; &lt;SPAN class="t"&gt;null:&lt;/SPAN&gt; &lt;SPAN class="t"&gt;MnT&lt;/SPAN&gt; &lt;SPAN class="t"&gt;purge&lt;/SPAN&gt; &lt;SPAN class="t"&gt;event&lt;/SPAN&gt; &lt;SPAN class="t"&gt;occurred&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class="t"&gt;MESSAGE=purging&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Tacacs&lt;/SPAN&gt; &lt;SPAN class="t"&gt;data&lt;/SPAN&gt; &lt;SPAN class="t"&gt;older&lt;/SPAN&gt; &lt;SPAN class="t"&gt;than&lt;/SPAN&gt; &lt;SPAN class="t"&gt;26-MAY-20,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="t"&gt;Is there anyway to forward the AAA logs to Splunk? I am using ISE version 2.3.0.298. Thank you.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jun 2020 03:42:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/forwarding-ise-authentication-logging-to-splunk/m-p/4109084#M561401</guid>
      <dc:creator>fdharmawan</dc:creator>
      <dc:date>2020-06-25T03:42:12Z</dc:date>
    </item>
    <item>
      <title>Re: Forwarding ISE Authentication Logging to Splunk</title>
      <link>https://community.cisco.com/t5/network-access-control/forwarding-ise-authentication-logging-to-splunk/m-p/4109277#M561411</link>
      <description>Make sure you update the logging categories in ISE to add the new target (splunk).  This should assist you in your journey: &lt;A href="http://www.network-node.com/blog/2017/7/2/integrating-ise-with-splunk" target="_blank"&gt;http://www.network-node.com/blog/2017/7/2/integrating-ise-with-splunk&lt;/A&gt;&lt;BR /&gt;HTH!</description>
      <pubDate>Thu, 25 Jun 2020 12:41:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/forwarding-ise-authentication-logging-to-splunk/m-p/4109277#M561411</guid>
      <dc:creator>Mike.Cifelli</dc:creator>
      <dc:date>2020-06-25T12:41:49Z</dc:date>
    </item>
  </channel>
</rss>

