<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Message Catalog Severity Level in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/message-catalog-severity-level/m-p/4282425#M565118</link>
    <description>&lt;P&gt;//del sorry old thread&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 29 Jan 2021 19:29:03 GMT</pubDate>
    <dc:creator>iambelik1</dc:creator>
    <dc:date>2021-01-29T19:29:03Z</dc:date>
    <item>
      <title>Message Catalog Severity Level</title>
      <link>https://community.cisco.com/t5/network-access-control/message-catalog-severity-level/m-p/3951935#M455993</link>
      <description>&lt;P&gt;We have our ISE deployment pushing logs to a splunk server. We are looking at message class "PSN-Heartbeat" and noticed that message code in this class have a severity level of "Notice".&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are interested in the following message codes:&lt;/P&gt;&lt;P&gt;60057 (A PSN node went down)&lt;/P&gt;&lt;P&gt;60058 (Initial Status of heartbeat system)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The issue here is that the system and operational logging category in ISE has a severity level of "INFO".&amp;nbsp; These message class has a severity level of "Notice" there for its not being pushed to the log servers. There is not an option to reduce the logging option to Notice so the splunk server can pick up the triggered message_code.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The object here is to get a Splunk log that identifies the status of each of our PSN nodes. Especially when one of our PSN nodes goes down.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can the message catalog have its severity levels changed? and if so, how?&lt;/P&gt;</description>
      <pubDate>Fri, 01 Nov 2019 22:26:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/message-catalog-severity-level/m-p/3951935#M455993</guid>
      <dc:creator>baker82</dc:creator>
      <dc:date>2019-11-01T22:26:17Z</dc:date>
    </item>
    <item>
      <title>Re: Message Catalog Severity Level</title>
      <link>https://community.cisco.com/t5/network-access-control/message-catalog-severity-level/m-p/3952049#M455995</link>
      <description>&lt;P&gt;NOTICE is hidden level between WARN and INFO. If INFO is selected, you should get all logs including NOTICE. You can't change log levels of individual messages, but can change per catalog by going to &lt;STRONG&gt;Administration &amp;gt; System &amp;gt; Logging &amp;gt; Logging Categories&lt;/STRONG&gt;.&lt;/P&gt;</description>
      <pubDate>Sat, 02 Nov 2019 07:09:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/message-catalog-severity-level/m-p/3952049#M455995</guid>
      <dc:creator>howon</dc:creator>
      <dc:date>2019-11-02T07:09:06Z</dc:date>
    </item>
    <item>
      <title>Re: Message Catalog Severity Level</title>
      <link>https://community.cisco.com/t5/network-access-control/message-catalog-severity-level/m-p/4282425#M565118</link>
      <description>&lt;P&gt;//del sorry old thread&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 29 Jan 2021 19:29:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/message-catalog-severity-level/m-p/4282425#M565118</guid>
      <dc:creator>iambelik1</dc:creator>
      <dc:date>2021-01-29T19:29:03Z</dc:date>
    </item>
  </channel>
</rss>

