<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Extend logging for radius live logs in ISE in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/extend-logging-for-radius-live-logs-in-ise/m-p/4123835#M561852</link>
    <description>&lt;P&gt;‘clock timezone EST5EDT’ in config mode in ISE SSH console will update logs with daylight savings. As to why that isn't an option in the GUI is beyond me. It will reboot services, so do it after hours.&lt;/P&gt;</description>
    <pubDate>Wed, 22 Jul 2020 21:35:37 GMT</pubDate>
    <dc:creator>ryan14</dc:creator>
    <dc:date>2020-07-22T21:35:37Z</dc:date>
    <item>
      <title>Extend logging for radius live logs in ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/extend-logging-for-radius-live-logs-in-ise/m-p/4117726#M561672</link>
      <description>&lt;P&gt;Is there a way to extend logging for radius logs on ISE 2.6? I have tried going to admin -&amp;gt; logging -&amp;gt; log settings and changing the default to 30 days but my live logs for radius do not appear to be using that setting. I also tried pointing ISE to my external syslog but do not see any messages being sent to it. Is there somewhere else I should be looking to set either function?&lt;/P&gt;</description>
      <pubDate>Mon, 13 Jul 2020 14:39:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/extend-logging-for-radius-live-logs-in-ise/m-p/4117726#M561672</guid>
      <dc:creator>ryan14</dc:creator>
      <dc:date>2020-07-13T14:39:45Z</dc:date>
    </item>
    <item>
      <title>Re: Extend logging for radius live logs in ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/extend-logging-for-radius-live-logs-in-ise/m-p/4118033#M561680</link>
      <description>&lt;P&gt;The ISE appliances have a finite amount of storage to use for local logs. They operate like a ring buffer in which the older logs are deleted to make room for new logs.&lt;/P&gt;
&lt;P&gt;You should be using an external syslog server for historical logging/reporting. See the following example for how to configure ISE to send the necessary logs to an external server:&lt;/P&gt;
&lt;P&gt;&lt;A title="Integrating ISE with Splunk for Reporting" href="http://www.network-node.com/blog/2017/7/2/integrating-ise-with-splunk" target="_blank" rel="noopener"&gt;Integrating ISE with Splunk for Reporting&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 13 Jul 2020 23:31:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/extend-logging-for-radius-live-logs-in-ise/m-p/4118033#M561680</guid>
      <dc:creator>Greg Gibbs</dc:creator>
      <dc:date>2020-07-13T23:31:50Z</dc:date>
    </item>
    <item>
      <title>Re: Extend logging for radius live logs in ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/extend-logging-for-radius-live-logs-in-ise/m-p/4118214#M561685</link>
      <description>Worth asking, but are you using the advanced filters on the reports with a date range longer than 30 days?  The drop down presets don't provide more than 30 days since that's the default log retention anyways.  &lt;BR /&gt;&lt;BR /&gt;Another aspect to this is storage, as Greg mentioned, there is a finite storage for log retention. If you don't have enough storage, then ISE will ignore the number of days set and start purging the oldest logs to keep enough disk space free. You can check this in the admin &amp;gt; maintenance &amp;gt; operational data purging menu too.  If you hover over the usage bar, it will give you some additional info. &lt;BR /&gt;https://&amp;lt;ise pan ip&amp;gt;/admin/#administration/administration_system/administration_system_backup/data_purging&lt;BR /&gt;&lt;BR /&gt;Gregs Splunk reference link will walk you through setting up the categories of syslogs you want to export.</description>
      <pubDate>Tue, 14 Jul 2020 06:57:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/extend-logging-for-radius-live-logs-in-ise/m-p/4118214#M561685</guid>
      <dc:creator>Damien Miller</dc:creator>
      <dc:date>2020-07-14T06:57:03Z</dc:date>
    </item>
    <item>
      <title>Re: Extend logging for radius live logs in ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/extend-logging-for-radius-live-logs-in-ise/m-p/4118411#M561688</link>
      <description>&lt;P&gt;Yeah part of it was user error on my part. I didn't realize the reports pulled data from a longer period compared to live radius logs.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The retention options you pointed out are definitely helpful. If I enable a repository, can ISE search that for reporting for something longer than the configured retention period? Or does ISE purge data stored locally + what has been sent to repository?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also, is the logs don't show times in daylight savings? I am using the latest patch 6 on 2.6. I verified via the CLI the timezone is set correctly.&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jul 2020 12:51:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/extend-logging-for-radius-live-logs-in-ise/m-p/4118411#M561688</guid>
      <dc:creator>ryan14</dc:creator>
      <dc:date>2020-07-14T12:51:19Z</dc:date>
    </item>
    <item>
      <title>Re: Extend logging for radius live logs in ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/extend-logging-for-radius-live-logs-in-ise/m-p/4118821#M561701</link>
      <description>&lt;P&gt;A repository is just an external file storage location (FTP, TFTP, etc) on which ISE can store scheduled or manually run reports. Once ISE stores the reports in the requested format (PDF, CSV), it has no ability to parse/query or control the retention for those reports. You would need to use additional tools to parse the data in the reports and control data retention for those reports.&lt;/P&gt;
&lt;P&gt;The amount of reportable data that the MnT node can store depends on the ISE version and disk size. See the &lt;A href="https://community.cisco.com/t5/security-documents/ise-performance-amp-scale/ta-p/3642148#toc-hId-1933370511" target="_blank" rel="noopener"&gt;ISE Performance &amp;amp; Scale&lt;/A&gt; page for MnT log retention estimations.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For the time issue, there have been a few bugs fixed related to time including the one below that is listed as fixed in patch 7. You might update to patch 7 to see if the issue is resolved or contact TAC if not.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvt08143" target="_self"&gt;CSCvt08143&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jul 2020 23:50:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/extend-logging-for-radius-live-logs-in-ise/m-p/4118821#M561701</guid>
      <dc:creator>Greg Gibbs</dc:creator>
      <dc:date>2020-07-14T23:50:40Z</dc:date>
    </item>
    <item>
      <title>Re: Extend logging for radius live logs in ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/extend-logging-for-radius-live-logs-in-ise/m-p/4123835#M561852</link>
      <description>&lt;P&gt;‘clock timezone EST5EDT’ in config mode in ISE SSH console will update logs with daylight savings. As to why that isn't an option in the GUI is beyond me. It will reboot services, so do it after hours.&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jul 2020 21:35:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/extend-logging-for-radius-live-logs-in-ise/m-p/4123835#M561852</guid>
      <dc:creator>ryan14</dc:creator>
      <dc:date>2020-07-22T21:35:37Z</dc:date>
    </item>
  </channel>
</rss>

