<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Onboarding Cisco ISE onto QRadar 7.4.0 FP3 - Issues encountered in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/onboarding-cisco-ise-onto-qradar-7-4-0-fp3-issues-encountered/m-p/4173510#M563517</link>
    <description>&lt;P&gt;Hello,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are a Managed Security Services company trying to onboard a customer's Cisco ISE device onto&amp;nbsp;QRadar 7.4.0 FP3.&lt;/P&gt;&lt;P&gt;- The logs are landing at the QRadar event collector.&lt;/P&gt;&lt;P&gt;- They are arriving as UDP multiline, which is what QRadar expects.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ISSUE: However, the &lt;A href="https://www.ibm.com/support/knowledgecenter/SS42VS_DSM/com.ibm.dsm.doc/c_dsm_guide_Cisco_ISE_overview.html" target="_self"&gt;DSM guide&lt;/A&gt; produced by IBM seems to deal with the older versions of QRadar, hence the log source settings are a little different. I need your guidance on onboarding it to&amp;nbsp;QRadar 7.4.0 FP3.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here are variations/differences/gaps from the DSM guide which we saw:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1. As seen in screenshot # 1 below, the field Source Name Formatting String is mandatory when you create the log source. However, that field wasn't present in the previous QRadar versions. What value should be put there?&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ISE2.png" style="width: 585px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/86898iFCC6C9E3DF4916B2/image-size/large?v=v2&amp;amp;px=999" role="button" title="ISE2.png" alt="ISE2.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2. As seen in screenshot # 2 below, when you enable Show Advanced Options, some more options show up. What should be enabled in the advanced settings?&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ISE1.png" style="width: 585px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/86899i5C38C3145A91D9DB/image-size/large?v=v2&amp;amp;px=999" role="button" title="ISE1.png" alt="ISE1.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;3. As seen in screenshot # 3 below, we have selected the Protocol Type as UDP Multiline Syslog (instead of Syslog). Would the QRadar DSM automatically re-assemble the log messages coming over multiple packets? If we select the Protocol Type as Syslog, then the first message gets parsed but the remaining ones are not re-assembled. In any case, the recommended option in the DSM guide is UDP Multiline Syslog, which is not working.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ISE3.png" style="width: 590px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/86895iE1492CF80D2A5CC4/image-size/large?v=v2&amp;amp;px=999" role="button" title="ISE3.png" alt="ISE3.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would appreciate some help on the same. Apart from the highlighted, the only difference is that we are sending it to a non-default port at the event collector (527 instead of 517).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best,&lt;/P&gt;&lt;P&gt;Pukhraj&lt;/P&gt;</description>
    <pubDate>Mon, 26 Oct 2020 09:13:50 GMT</pubDate>
    <dc:creator>Singh94100</dc:creator>
    <dc:date>2020-10-26T09:13:50Z</dc:date>
    <item>
      <title>Onboarding Cisco ISE onto QRadar 7.4.0 FP3 - Issues encountered</title>
      <link>https://community.cisco.com/t5/network-access-control/onboarding-cisco-ise-onto-qradar-7-4-0-fp3-issues-encountered/m-p/4173510#M563517</link>
      <description>&lt;P&gt;Hello,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are a Managed Security Services company trying to onboard a customer's Cisco ISE device onto&amp;nbsp;QRadar 7.4.0 FP3.&lt;/P&gt;&lt;P&gt;- The logs are landing at the QRadar event collector.&lt;/P&gt;&lt;P&gt;- They are arriving as UDP multiline, which is what QRadar expects.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ISSUE: However, the &lt;A href="https://www.ibm.com/support/knowledgecenter/SS42VS_DSM/com.ibm.dsm.doc/c_dsm_guide_Cisco_ISE_overview.html" target="_self"&gt;DSM guide&lt;/A&gt; produced by IBM seems to deal with the older versions of QRadar, hence the log source settings are a little different. I need your guidance on onboarding it to&amp;nbsp;QRadar 7.4.0 FP3.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here are variations/differences/gaps from the DSM guide which we saw:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1. As seen in screenshot # 1 below, the field Source Name Formatting String is mandatory when you create the log source. However, that field wasn't present in the previous QRadar versions. What value should be put there?&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ISE2.png" style="width: 585px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/86898iFCC6C9E3DF4916B2/image-size/large?v=v2&amp;amp;px=999" role="button" title="ISE2.png" alt="ISE2.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2. As seen in screenshot # 2 below, when you enable Show Advanced Options, some more options show up. What should be enabled in the advanced settings?&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ISE1.png" style="width: 585px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/86899i5C38C3145A91D9DB/image-size/large?v=v2&amp;amp;px=999" role="button" title="ISE1.png" alt="ISE1.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;3. As seen in screenshot # 3 below, we have selected the Protocol Type as UDP Multiline Syslog (instead of Syslog). Would the QRadar DSM automatically re-assemble the log messages coming over multiple packets? If we select the Protocol Type as Syslog, then the first message gets parsed but the remaining ones are not re-assembled. In any case, the recommended option in the DSM guide is UDP Multiline Syslog, which is not working.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ISE3.png" style="width: 590px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/86895iE1492CF80D2A5CC4/image-size/large?v=v2&amp;amp;px=999" role="button" title="ISE3.png" alt="ISE3.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would appreciate some help on the same. Apart from the highlighted, the only difference is that we are sending it to a non-default port at the event collector (527 instead of 517).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best,&lt;/P&gt;&lt;P&gt;Pukhraj&lt;/P&gt;</description>
      <pubDate>Mon, 26 Oct 2020 09:13:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/onboarding-cisco-ise-onto-qradar-7-4-0-fp3-issues-encountered/m-p/4173510#M563517</guid>
      <dc:creator>Singh94100</dc:creator>
      <dc:date>2020-10-26T09:13:50Z</dc:date>
    </item>
    <item>
      <title>Re: Onboarding Cisco ISE onto QRadar 7.4.0 FP3 - Issues encountered</title>
      <link>https://community.cisco.com/t5/network-access-control/onboarding-cisco-ise-onto-qradar-7-4-0-fp3-issues-encountered/m-p/4173734#M563522</link>
      <description>&lt;P&gt;I'd recommend opening a ticket with support team.&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/216120-ise-security-ecosystem-integration-guide.html#anc49" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/216120-ise-security-ecosystem-integration-guide.html#anc49&lt;/A&gt;&lt;/P&gt;&lt;P&gt;its under the troubleshooting guide&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.cisco.com/t5/security-documents/ibm-qradar-pxgrid-app-troubleshooting/ta-p/3891487" target="_blank"&gt;https://community.cisco.com/t5/security-documents/ibm-qradar-pxgrid-app-troubleshooting/ta-p/3891487&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 26 Oct 2020 15:11:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/onboarding-cisco-ise-onto-qradar-7-4-0-fp3-issues-encountered/m-p/4173734#M563522</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2020-10-26T15:11:31Z</dc:date>
    </item>
    <item>
      <title>Re: Onboarding Cisco ISE onto QRadar 7.4.0 FP3 - Issues encountered</title>
      <link>https://community.cisco.com/t5/network-access-control/onboarding-cisco-ise-onto-qradar-7-4-0-fp3-issues-encountered/m-p/4304216#M565991</link>
      <description>&lt;P&gt;Hi could please give the solution details? I've the same problem here.&lt;/P&gt;</description>
      <pubDate>Tue, 09 Mar 2021 19:54:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/onboarding-cisco-ise-onto-qradar-7-4-0-fp3-issues-encountered/m-p/4304216#M565991</guid>
      <dc:creator>Wanderley Viana</dc:creator>
      <dc:date>2021-03-09T19:54:05Z</dc:date>
    </item>
    <item>
      <title>Re: Onboarding Cisco ISE onto QRadar 7.4.0 FP3 - Issues encountered</title>
      <link>https://community.cisco.com/t5/network-access-control/onboarding-cisco-ise-onto-qradar-7-4-0-fp3-issues-encountered/m-p/4305057#M566019</link>
      <description>&lt;P&gt;Please look at the latest qRadar guides under &lt;A href="http://cs.co/ise-guides" target="_blank"&gt;http://cs.co/ise-guides&lt;/A&gt;&amp;nbsp;if you're still having issues open a support ticket.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also this seems it might be a QRadar issue and nothing to do with the ISE QRadar app. I'd recommend a ticket with IBM.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please do share what you get so we can update guides&lt;/P&gt;</description>
      <pubDate>Wed, 10 Mar 2021 16:56:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/onboarding-cisco-ise-onto-qradar-7-4-0-fp3-issues-encountered/m-p/4305057#M566019</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2021-03-10T16:56:22Z</dc:date>
    </item>
  </channel>
</rss>

