<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE ERS filter endpoints by endpoint group in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-ers-filter-endpoints-by-endpoint-group/m-p/3709915#M56425</link>
    <description>&lt;P&gt;I realize this question is a few years old, but I had the same question.&amp;nbsp; According to the documentation you can filter endpoints using these attributes:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE class="prettyprint prettyprinted"&gt;&lt;SPAN class="typ"&gt;Filter&lt;/SPAN&gt;&lt;SPAN class="pun"&gt;:&lt;/SPAN&gt; &lt;SPAN class="pun"&gt;[&lt;/SPAN&gt;&lt;SPAN class="pln"&gt;portalUser&lt;/SPAN&gt;&lt;SPAN class="pun"&gt;,&lt;/SPAN&gt;&lt;SPAN class="pln"&gt; staticProfileAssignment&lt;/SPAN&gt;&lt;SPAN class="pun"&gt;,&lt;/SPAN&gt;&lt;SPAN class="pln"&gt; profileId&lt;/SPAN&gt;&lt;SPAN class="pun"&gt;,&lt;/SPAN&gt;&lt;SPAN class="pln"&gt; profile&lt;/SPAN&gt;&lt;SPAN class="pun"&gt;,&lt;/SPAN&gt;&lt;SPAN class="pln"&gt; groupId&lt;/SPAN&gt;&lt;SPAN class="pun"&gt;,&lt;/SPAN&gt;&lt;SPAN class="pln"&gt; staticGroupAssignment&lt;/SPAN&gt;&lt;SPAN class="pun"&gt;,&lt;/SPAN&gt;&lt;SPAN class="pln"&gt; mac&lt;/SPAN&gt;&lt;SPAN class="pun"&gt;]&lt;/SPAN&gt;&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So by first getting the groupId of the endpoint group, you can do a EQ filter to get all endpoints that are in the group.&amp;nbsp; The URL would look something like this:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://isenode.yourdomain.com:9060/ers/config/endpoint?filter=groupId.EQ.47c84980-bb7b-11e8-b1e2-0eb4d50b5f28" target="_blank"&gt;https://isenode.yourdomain.com:9060/ers/config/endpoint?filter=groupId.EQ.47c84980-bb7b-11e8-b1e2-0eb4d50b5f28&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 19 Sep 2018 21:12:04 GMT</pubDate>
    <dc:creator>sinkemlow</dc:creator>
    <dc:date>2018-09-19T21:12:04Z</dc:date>
    <item>
      <title>ISE ERS filter endpoints by endpoint group</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-ers-filter-endpoints-by-endpoint-group/m-p/2814538#M56424</link>
      <description>&lt;DIV class="field field-name-body field-type-text-with-summary field-label-hidden"&gt;
&lt;DIV class="field-items"&gt;Hi All!&lt;/DIV&gt;
&lt;DIV class="field-items"&gt;&lt;/DIV&gt;
&lt;DIV class="field-items"&gt;I am trying to retrieve all Endpoints in a particular EndpointGroup via the ISE ERS API. What I am trying is:&lt;/DIV&gt;
&lt;DIV class="field-items"&gt;&lt;/DIV&gt;
&lt;DIV class="field-items"&gt;Request:&lt;/DIV&gt;
&lt;PRE class="field-items prettyprint"&gt;GET &lt;A href="https://&amp;lt;ISE-ADMIN-NODE&amp;gt;:9060/ers/config/endpoint?size=10&amp;amp;sortdsc=name&amp;amp;filter=identityGroup.EQ.&amp;lt;GroupName&amp;gt;" target="_blank"&gt;https://&amp;lt;ISE-ADMIN-NODE&amp;gt;:9060/ers/config/endpoint?size=10&amp;amp;sortdsc=name&amp;amp;filter=identityGroup.EQ.&amp;lt;GroupName&amp;gt;&lt;/A&gt;&lt;BR /&gt;ACCEPT: application/vnd.com.cisco.ise.identity.endpoint.1.0+xml&lt;/PRE&gt;
&lt;DIV class="field-items"&gt;&lt;/DIV&gt;
&lt;DIV class="field-items"&gt;Response:&lt;/DIV&gt;
&lt;PRE class="field-items prettyprint"&gt;HTTP/1.1 400 Bad Request&lt;BR /&gt;&amp;lt;?xml version="1.0" encoding="utf-8" standalone="yes"?&amp;gt;&lt;BR /&gt;&amp;lt;ns2:ersResponse operation="GET-getAll-endpoint" xmlns:ns2="ers.ise.cisco.com"&amp;gt;&lt;BR /&gt;&amp;nbsp; &amp;lt;link type="application/xml" href="https://&amp;lt;ISE-ADMIN-NODE&amp;gt;:9060/ers/config/endpoint?size=10&amp;amp;amp;sortdsc=name&amp;amp;amp;filter=identityGroup.EQ.&amp;lt;GroupName&amp;gt;" rel="related"/&amp;gt;&lt;BR /&gt;&amp;nbsp; &amp;lt;messages&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;message code="Query string validation exception" type="ERROR"&amp;gt;&amp;lt;title&amp;gt;The filter field 'identityGroup' is not supported&amp;lt;/title&amp;gt;&amp;lt;/message&amp;gt;&lt;BR /&gt;&amp;nbsp; &amp;lt;/messages&amp;gt;&lt;BR /&gt;&amp;lt;/ns2:ersResponse&amp;gt;&lt;/PRE&gt;
&lt;DIV class="field-items"&gt;&lt;/DIV&gt;
&lt;DIV class="field-items"&gt;I have alredy tried 'identityGroup', 'staticGroup', 'group' and 'endpointGroup' as the field-name in the filter.&lt;/DIV&gt;
&lt;DIV class="field-items"&gt;&lt;/DIV&gt;
&lt;DIV class="field-items"&gt;&lt;/DIV&gt;
&lt;DIV class="field-items"&gt;Querying Users in a specific IdentityGroup works this way.&lt;/DIV&gt;
&lt;DIV class="field-items"&gt;&lt;/DIV&gt;
&lt;DIV class="field-items"&gt;&lt;/DIV&gt;
&lt;DIV class="field-items"&gt;Does anyone know of a way to achieve what I am trying (probably I am missing something obvious)?&lt;/DIV&gt;
&lt;DIV class="field-items"&gt;&lt;/DIV&gt;
&lt;DIV class="field-items"&gt;Thanks in advance,&lt;/DIV&gt;
&lt;DIV class="field-items"&gt;Michael Langerreiter&lt;/DIV&gt;
&lt;DIV class="field-items"&gt;&lt;/DIV&gt;
&lt;DIV class="field-items"&gt;&lt;/DIV&gt;
&lt;DIV class="field-items"&gt;&lt;/DIV&gt;
&lt;/DIV&gt;</description>
      <pubDate>Mon, 11 Mar 2019 06:18:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-ers-filter-endpoints-by-endpoint-group/m-p/2814538#M56424</guid>
      <dc:creator>Michael Langerreiter</dc:creator>
      <dc:date>2019-03-11T06:18:08Z</dc:date>
    </item>
    <item>
      <title>Re: ISE ERS filter endpoints by endpoint group</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-ers-filter-endpoints-by-endpoint-group/m-p/3709915#M56425</link>
      <description>&lt;P&gt;I realize this question is a few years old, but I had the same question.&amp;nbsp; According to the documentation you can filter endpoints using these attributes:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE class="prettyprint prettyprinted"&gt;&lt;SPAN class="typ"&gt;Filter&lt;/SPAN&gt;&lt;SPAN class="pun"&gt;:&lt;/SPAN&gt; &lt;SPAN class="pun"&gt;[&lt;/SPAN&gt;&lt;SPAN class="pln"&gt;portalUser&lt;/SPAN&gt;&lt;SPAN class="pun"&gt;,&lt;/SPAN&gt;&lt;SPAN class="pln"&gt; staticProfileAssignment&lt;/SPAN&gt;&lt;SPAN class="pun"&gt;,&lt;/SPAN&gt;&lt;SPAN class="pln"&gt; profileId&lt;/SPAN&gt;&lt;SPAN class="pun"&gt;,&lt;/SPAN&gt;&lt;SPAN class="pln"&gt; profile&lt;/SPAN&gt;&lt;SPAN class="pun"&gt;,&lt;/SPAN&gt;&lt;SPAN class="pln"&gt; groupId&lt;/SPAN&gt;&lt;SPAN class="pun"&gt;,&lt;/SPAN&gt;&lt;SPAN class="pln"&gt; staticGroupAssignment&lt;/SPAN&gt;&lt;SPAN class="pun"&gt;,&lt;/SPAN&gt;&lt;SPAN class="pln"&gt; mac&lt;/SPAN&gt;&lt;SPAN class="pun"&gt;]&lt;/SPAN&gt;&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So by first getting the groupId of the endpoint group, you can do a EQ filter to get all endpoints that are in the group.&amp;nbsp; The URL would look something like this:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://isenode.yourdomain.com:9060/ers/config/endpoint?filter=groupId.EQ.47c84980-bb7b-11e8-b1e2-0eb4d50b5f28" target="_blank"&gt;https://isenode.yourdomain.com:9060/ers/config/endpoint?filter=groupId.EQ.47c84980-bb7b-11e8-b1e2-0eb4d50b5f28&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 19 Sep 2018 21:12:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-ers-filter-endpoints-by-endpoint-group/m-p/3709915#M56425</guid>
      <dc:creator>sinkemlow</dc:creator>
      <dc:date>2018-09-19T21:12:04Z</dc:date>
    </item>
  </channel>
</rss>

