<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE-PIC not seeing Windows Logon events in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-pic-not-seeing-windows-logon-events/m-p/4549883#M572727</link>
    <description>&lt;P&gt;While you've listed the codes (and are mostly correct), it is actually an issue with the Audit Policy not being fully set.&amp;nbsp; This is something that isn't covered (at all) in the ISE/PIC documentation.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Check out the very well crafted answer over here:&lt;BR /&gt;&lt;A href="https://community.cisco.com/t5/network-access-control/ise-passiveid-and-wmi-pulling/m-p/3928476/highlight/true#M457053" target="_blank"&gt;https://community.cisco.com/t5/network-access-control/ise-passiveid-and-wmi-pulling/m-p/3928476/highlight/true#M457053&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 10 Feb 2022 20:25:11 GMT</pubDate>
    <dc:creator>purchasing</dc:creator>
    <dc:date>2022-02-10T20:25:11Z</dc:date>
    <item>
      <title>ISE-PIC not seeing Windows Logon events</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-pic-not-seeing-windows-logon-events/m-p/4318754#M566593</link>
      <description>&lt;P&gt;I'm trying to setup ISE-PIC 2.7 to replace the older Firepower User Agent software.&amp;nbsp; I've followed the how-to install, and the PassiveID setup wizard.&amp;nbsp; On the Providers pane I see my DCs all listed with an "UP" status (green check mark).&amp;nbsp; But I've only ever gotten a single session showing in ISE.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If I look at the event viewer on any of the DCs then I see &lt;EM&gt;&lt;STRONG&gt;LOTS&lt;/STRONG&gt; &lt;/EM&gt;of 4624 "Logon" events that correspond to granted kerberos tickets.&amp;nbsp; So I know the event auditing is working properly, it just doesn't seem that ISE is reading these events.&amp;nbsp; (Again, I saw a single session pop-up once, so it isn't that ISE is unable to talk to the DCs -- it feels like a filter criteria issue to me)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I did notice that the verbose logging for the Agents (currently not using the Agents, but did try at one point to see if they had a different result) seemed to imply that they were watching for 4768 &amp;amp; 4770 events.&amp;nbsp; While I'd include those in my "what to watch for list", I wouldn't make it exclusively those two events (I normally use&amp;nbsp;4624, 4768, 4769, and 4770 when looking for auths -- especially since I see all the 4624 logon events).&amp;nbsp; Does anyone which event IDs ISE-PIC is looking for (and which channels it is looking for them in)?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Has anyone else had an issue where ISE-PIC just wasn't seeing active sessions (and if you have, can you give pointers on what your fix[es] were)?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm currently running ISE-PIC 2.7 with the Active Directory providers in WMI mode.&amp;nbsp; I've tried both 2.7 &amp;amp; 3.0, and both of them with AD in WMI &amp;amp; Agent modes.&amp;nbsp; The setup is always smooth, and I can get my subscribers connected -- I just don't have a good session directory because ISE doesn't seem to see the active sessions on the DCs.&amp;nbsp; I see walkthroughs all over the place talking about how easy it is, and I'm sure that's normally true.&amp;nbsp; But I'm starting to have trouble with the old Firepower User Agent and would love to get this tested so I can justify getting the licenses in place and then get rid of the old agent.&lt;/P&gt;</description>
      <pubDate>Mon, 05 Apr 2021 15:29:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-pic-not-seeing-windows-logon-events/m-p/4318754#M566593</guid>
      <dc:creator>Russell Rockett</dc:creator>
      <dc:date>2021-04-05T15:29:19Z</dc:date>
    </item>
    <item>
      <title>Re: ISE-PIC not seeing Windows Logon events</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-pic-not-seeing-windows-logon-events/m-p/4549883#M572727</link>
      <description>&lt;P&gt;While you've listed the codes (and are mostly correct), it is actually an issue with the Audit Policy not being fully set.&amp;nbsp; This is something that isn't covered (at all) in the ISE/PIC documentation.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Check out the very well crafted answer over here:&lt;BR /&gt;&lt;A href="https://community.cisco.com/t5/network-access-control/ise-passiveid-and-wmi-pulling/m-p/3928476/highlight/true#M457053" target="_blank"&gt;https://community.cisco.com/t5/network-access-control/ise-passiveid-and-wmi-pulling/m-p/3928476/highlight/true#M457053&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Feb 2022 20:25:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-pic-not-seeing-windows-logon-events/m-p/4549883#M572727</guid>
      <dc:creator>purchasing</dc:creator>
      <dc:date>2022-02-10T20:25:11Z</dc:date>
    </item>
  </channel>
</rss>

