<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ISE operational backup content to syslog instead of backups in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-operational-backup-content-to-syslog-instead-of-backups/m-p/4653212#M576254</link>
    <description>&lt;P&gt;We found this thread: &lt;A href="https://community.cisco.com/t5/network-access-control/ise-operational-backup-content/td-p/4184440" target="_blank"&gt;https://community.cisco.com/t5/network-access-control/ise-operational-backup-content/td-p/4184440&lt;/A&gt;&amp;nbsp; where it indicates that the Operational Data Backup contained basically RADIUS and TACACS logs.&lt;/P&gt;&lt;P&gt;We log most RADIUS and TACACS data to syslog from ISE already, which means that the backups are potentially quite a bit of redundant data, and excess storage usage.&lt;/P&gt;&lt;P&gt;What logging options on ISE would allow us to log all the operational data to syslog and then not worry about the operational data backup at all?&amp;nbsp; Is that even possible?&lt;/P&gt;&lt;P&gt;We fully understand that sysylog will require different talents to generate reports than the GUI, but we already have talent in shop and would only need to determine the various record layouts.&lt;/P&gt;&lt;P&gt;ISE v3.1+ patches&lt;/P&gt;</description>
    <pubDate>Tue, 19 Jul 2022 17:03:41 GMT</pubDate>
    <dc:creator>wags</dc:creator>
    <dc:date>2022-07-19T17:03:41Z</dc:date>
    <item>
      <title>ISE operational backup content to syslog instead of backups</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-operational-backup-content-to-syslog-instead-of-backups/m-p/4653212#M576254</link>
      <description>&lt;P&gt;We found this thread: &lt;A href="https://community.cisco.com/t5/network-access-control/ise-operational-backup-content/td-p/4184440" target="_blank"&gt;https://community.cisco.com/t5/network-access-control/ise-operational-backup-content/td-p/4184440&lt;/A&gt;&amp;nbsp; where it indicates that the Operational Data Backup contained basically RADIUS and TACACS logs.&lt;/P&gt;&lt;P&gt;We log most RADIUS and TACACS data to syslog from ISE already, which means that the backups are potentially quite a bit of redundant data, and excess storage usage.&lt;/P&gt;&lt;P&gt;What logging options on ISE would allow us to log all the operational data to syslog and then not worry about the operational data backup at all?&amp;nbsp; Is that even possible?&lt;/P&gt;&lt;P&gt;We fully understand that sysylog will require different talents to generate reports than the GUI, but we already have talent in shop and would only need to determine the various record layouts.&lt;/P&gt;&lt;P&gt;ISE v3.1+ patches&lt;/P&gt;</description>
      <pubDate>Tue, 19 Jul 2022 17:03:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-operational-backup-content-to-syslog-instead-of-backups/m-p/4653212#M576254</guid>
      <dc:creator>wags</dc:creator>
      <dc:date>2022-07-19T17:03:41Z</dc:date>
    </item>
    <item>
      <title>Re: ISE operational backup content to syslog instead of backups</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-operational-backup-content-to-syslog-instead-of-backups/m-p/4653228#M576255</link>
      <description>&lt;P&gt;This is pretty easy to do and done quite frequently. It won't be done as a backup but as a new syslog exporter.&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Create a new remote logging target here&amp;nbsp;&lt;A href="https://&amp;lt;your" target="_blank"&gt;https://&amp;lt;your-&lt;/A&gt;ise-node&amp;gt;/admin/#administration/administration_system/administration_system_logging/remote_log&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="rlt.JPG" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/157570iEDA5CAEC21BE9637/image-size/large?v=v2&amp;amp;px=999" role="button" title="rlt.JPG" alt="rlt.JPG" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;LI&gt;Add the new syslog target to the logging categories here&amp;nbsp;&lt;A href="https://your-ise-node/admin/#administration/administration_system/administration_system_logging/logging_categories" target="_blank"&gt;https://your-ise-node/admin/#administration/administration_system/administration_system_logging/logging_categories&lt;/A&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="lc.JPG" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/157573i11DE55A38B8543B3/image-size/large?v=v2&amp;amp;px=999" role="button" title="lc.JPG" alt="lc.JPG" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;Depending on what you want to report from the syslog server you will need to enable those logging categories for export. To start you would probably want aaa authentication failed and passed, aaa radius and tacacs accounting as that's the primary data found within the operational backup.&amp;nbsp;&lt;/LI&gt;
&lt;/OL&gt;</description>
      <pubDate>Tue, 19 Jul 2022 17:25:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-operational-backup-content-to-syslog-instead-of-backups/m-p/4653228#M576255</guid>
      <dc:creator>Damien Miller</dc:creator>
      <dc:date>2022-07-19T17:25:26Z</dc:date>
    </item>
    <item>
      <title>Re: ISE operational backup content to syslog instead of backups</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-operational-backup-content-to-syslog-instead-of-backups/m-p/4653240#M576256</link>
      <description>&lt;P&gt;Thanks for the reply!&amp;nbsp; &amp;nbsp;Do you know where there might be specific Cisco documentation?&amp;nbsp; Something that we can point to for an auditor who might think differently about the subject?&lt;/P&gt;&lt;P&gt;We have those already set up because we have historically used syslog so heavily. Again thanks!&lt;/P&gt;</description>
      <pubDate>Tue, 19 Jul 2022 17:44:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-operational-backup-content-to-syslog-instead-of-backups/m-p/4653240#M576256</guid>
      <dc:creator>wags</dc:creator>
      <dc:date>2022-07-19T17:44:13Z</dc:date>
    </item>
    <item>
      <title>Re: ISE operational backup content to syslog instead of backups</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-operational-backup-content-to-syslog-instead-of-backups/m-p/4653355#M576262</link>
      <description>&lt;P class="lia-align-justify"&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/320848"&gt;@wags&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;please try the following: &lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/3-1/admin_guide/b_ise_admin_3_1/b_ISE_admin_31_maintain_monitor.html#reference_BAFBA5FA046A45938810A5DF04C00591" target="_blank" rel="noopener"&gt;Cisco ISE Maintain and Monitor&lt;/A&gt;, search for &lt;STRONG&gt;Cisco ISE Logging Mechanism&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;Hope this helps !!!&lt;/P&gt;</description>
      <pubDate>Tue, 19 Jul 2022 22:47:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-operational-backup-content-to-syslog-instead-of-backups/m-p/4653355#M576262</guid>
      <dc:creator>Marcelo Morais</dc:creator>
      <dc:date>2022-07-19T22:47:32Z</dc:date>
    </item>
  </channel>
</rss>

