<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Logs in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/logs/m-p/4517196#M571605</link>
    <description>&lt;P&gt;Hi Team,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In our Infra devices have been integrated into the Cisco ISE for device Authentication. I need some help with log fetching.&lt;/P&gt;&lt;P&gt;Post tacacs authentication only the end-users can do the device configuration changes.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now one of the users had done the changes in the device but we don't know which user had been made.&lt;/P&gt;&lt;P&gt;So we need your help to find out the below details based on the log reporting.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1. How to fetch the log report for the last 7 days?&lt;/P&gt;&lt;P&gt;2. Who all are the users can login into the specific device for the past 7 days?&lt;/P&gt;&lt;P&gt;3. And what all are the configuration changes happened to the specific device?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please clarify the above details ASAP.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;RK&lt;/P&gt;</description>
    <pubDate>Thu, 10 Mar 2022 07:15:12 GMT</pubDate>
    <dc:creator>netops044</dc:creator>
    <dc:date>2022-03-10T07:15:12Z</dc:date>
    <item>
      <title>Logs</title>
      <link>https://community.cisco.com/t5/network-access-control/logs/m-p/4517196#M571605</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In our Infra devices have been integrated into the Cisco ISE for device Authentication. I need some help with log fetching.&lt;/P&gt;&lt;P&gt;Post tacacs authentication only the end-users can do the device configuration changes.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now one of the users had done the changes in the device but we don't know which user had been made.&lt;/P&gt;&lt;P&gt;So we need your help to find out the below details based on the log reporting.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1. How to fetch the log report for the last 7 days?&lt;/P&gt;&lt;P&gt;2. Who all are the users can login into the specific device for the past 7 days?&lt;/P&gt;&lt;P&gt;3. And what all are the configuration changes happened to the specific device?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please clarify the above details ASAP.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;RK&lt;/P&gt;</description>
      <pubDate>Thu, 10 Mar 2022 07:15:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/logs/m-p/4517196#M571605</guid>
      <dc:creator>netops044</dc:creator>
      <dc:date>2022-03-10T07:15:12Z</dc:date>
    </item>
    <item>
      <title>Re: Logs</title>
      <link>https://community.cisco.com/t5/network-access-control/logs/m-p/4517534#M571613</link>
      <description>&lt;P&gt;See the section on &lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/3-1/admin_guide/b_ise_admin_3_1/b_ISE_admin_31_maintain_monitor.html#concept_BBDE3C7FC9074AEB8B6C487FF3A25932" target="_blank" rel="noopener"&gt;Cisco ISE Reports in the Admin Guide&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;In the Device Administration section of the Reports, you will find TACACS Accounting, Authentication, and Authorization and TACACS Command Accounting reports. If you have these features enabled on the network device, you should see the information you're looking for there.&lt;/P&gt;</description>
      <pubDate>Sun, 12 Dec 2021 21:31:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/logs/m-p/4517534#M571613</guid>
      <dc:creator>Greg Gibbs</dc:creator>
      <dc:date>2021-12-12T21:31:46Z</dc:date>
    </item>
    <item>
      <title>Re: Logs</title>
      <link>https://community.cisco.com/t5/network-access-control/logs/m-p/4532264#M572242</link>
      <description>&lt;P&gt;Hello Gibbs,&lt;/P&gt;&lt;P&gt;Thanks for providing the idea. I have one more query, please clarify.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have created one new user in the Tacacs server. Now I have query about how to provide access to the user for some of the specific devices alone? We integrated almost 500 devices into the cisco ISE but the main objective is the created user wouldn't access all the devices, it should access the specific devices only.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;RK&lt;/P&gt;</description>
      <pubDate>Sun, 16 Jan 2022 14:57:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/logs/m-p/4532264#M572242</guid>
      <dc:creator>netops044</dc:creator>
      <dc:date>2022-01-16T14:57:37Z</dc:date>
    </item>
    <item>
      <title>Re: Logs</title>
      <link>https://community.cisco.com/t5/network-access-control/logs/m-p/4532315#M572247</link>
      <description>&lt;P&gt;If I understand correctly, you have a set of network devices to which a restricted admin user/group should have access. Ideally, you want to use groups where possible in ISE to improve the ability to scale. One way you could achieve this would be:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Create a new root-level Network Device Group (e.g. 'Restricted State') with two child groups (e.g. 'Restricted' and 'Non-Restricted)&lt;/LI&gt;
&lt;LI&gt;Update the relevant network device configurations to use the 'Restricted' value (you can do this in bulk using CSV export/import or via API)&lt;/LI&gt;
&lt;LI&gt;(Optionally) Create a User Identity Group for your restricted user(s)&lt;/LI&gt;
&lt;LI&gt;Update your Device Admin AuthZ Policy to match on the groups you created&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screen Shot 2022-01-17 at 8.37.53 am.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/141378iF72192140F77DB21/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screen Shot 2022-01-17 at 8.37.53 am.png" alt="Screen Shot 2022-01-17 at 8.37.53 am.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 16 Jan 2022 21:39:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/logs/m-p/4532315#M572247</guid>
      <dc:creator>Greg Gibbs</dc:creator>
      <dc:date>2022-01-16T21:39:33Z</dc:date>
    </item>
    <item>
      <title>Re: Logs</title>
      <link>https://community.cisco.com/t5/network-access-control/logs/m-p/4533377#M572278</link>
      <description>&lt;P&gt;Hi Gibbs,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for providing the suggestion.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you please share any reference link or websites? I am a beginner for the cisco ise and we aren't aware deep in this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&amp;nbsp;R K&lt;/P&gt;</description>
      <pubDate>Tue, 18 Jan 2022 15:25:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/logs/m-p/4533377#M572278</guid>
      <dc:creator>netops044</dc:creator>
      <dc:date>2022-01-18T15:25:11Z</dc:date>
    </item>
    <item>
      <title>Re: Logs</title>
      <link>https://community.cisco.com/t5/network-access-control/logs/m-p/4533644#M572281</link>
      <description>&lt;P&gt;You should start with the &lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/3-0/admin_guide/b_ISE_admin_3_0.html" target="_blank" rel="noopener"&gt;Admin Guide&lt;/A&gt; and &lt;A href="https://community.cisco.com/t5/security-documents/cisco-ise-amp-nac-resources/ta-p/3621621#Learn" target="_blank" rel="noopener"&gt;learning resource links&lt;/A&gt; documented here in the NAC Community.&lt;/P&gt;</description>
      <pubDate>Tue, 18 Jan 2022 21:20:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/logs/m-p/4533644#M572281</guid>
      <dc:creator>Greg Gibbs</dc:creator>
      <dc:date>2022-01-18T21:20:24Z</dc:date>
    </item>
  </channel>
</rss>

