<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cisco ISE Syslog Target Capture in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-ise-syslog-target-capture/m-p/4703532#M577769</link>
    <description>&lt;P&gt;Is there a way to troubleshoot or validate that Cisco ISE is sending syslogs to a "Remote Logging Target"?&lt;BR /&gt;I'm trying to set this up with QRadar however its showing that its not receieving any logs from ISE. I've confirmed that IBM has ISE packages to support it but I'm concerned because it says it supports versions 1.1 to 2.2 (seems very dated). Im running 3.1P3 at the moment.&amp;nbsp;I've setup the logging categories to include the new target but still no luck.&amp;nbsp;There is no firewalls between ISE and QRadar.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 14 Oct 2022 18:22:49 GMT</pubDate>
    <dc:creator>Lucas Borza</dc:creator>
    <dc:date>2022-10-14T18:22:49Z</dc:date>
    <item>
      <title>Cisco ISE Syslog Target Capture</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-syslog-target-capture/m-p/4703532#M577769</link>
      <description>&lt;P&gt;Is there a way to troubleshoot or validate that Cisco ISE is sending syslogs to a "Remote Logging Target"?&lt;BR /&gt;I'm trying to set this up with QRadar however its showing that its not receieving any logs from ISE. I've confirmed that IBM has ISE packages to support it but I'm concerned because it says it supports versions 1.1 to 2.2 (seems very dated). Im running 3.1P3 at the moment.&amp;nbsp;I've setup the logging categories to include the new target but still no luck.&amp;nbsp;There is no firewalls between ISE and QRadar.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 14 Oct 2022 18:22:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-syslog-target-capture/m-p/4703532#M577769</guid>
      <dc:creator>Lucas Borza</dc:creator>
      <dc:date>2022-10-14T18:22:49Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE Syslog Target Capture</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-syslog-target-capture/m-p/4703535#M577770</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1419709"&gt;@Lucas Borza&lt;/a&gt; run tcpdump on ISE and filter on the syslog IP address to determine whether ISE attempts to communicate.&lt;/P&gt;</description>
      <pubDate>Fri, 14 Oct 2022 18:26:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-syslog-target-capture/m-p/4703535#M577770</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2022-10-14T18:26:41Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE Syslog Target Capture</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-syslog-target-capture/m-p/4703536#M577771</link>
      <description>&lt;P&gt;This might sound silly, but I've tried that and its empty. The syslogs are sending in UDP. Would the TCP dump cover that?&lt;/P&gt;</description>
      <pubDate>Fri, 14 Oct 2022 18:27:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-syslog-target-capture/m-p/4703536#M577771</guid>
      <dc:creator>Lucas Borza</dc:creator>
      <dc:date>2022-10-14T18:27:33Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE Syslog Target Capture</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-syslog-target-capture/m-p/4703539#M577772</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1419709"&gt;@Lucas Borza&lt;/a&gt; have you assigned the remote logging server as a target under the required logging categories?&lt;/P&gt;</description>
      <pubDate>Fri, 14 Oct 2022 18:36:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-syslog-target-capture/m-p/4703539#M577772</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2022-10-14T18:36:12Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE Syslog Target Capture</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-syslog-target-capture/m-p/4703544#M577773</link>
      <description>&lt;P&gt;Yes. It turns out the team that manages QRadar had an error in their setup, and they resolved it. I would hope that the TCPDUMP would cover the UDP traffic to at least prove that I am sending the logs.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 14 Oct 2022 19:04:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-syslog-target-capture/m-p/4703544#M577773</guid>
      <dc:creator>PRANetworkTeam</dc:creator>
      <dc:date>2022-10-14T19:04:24Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE Syslog Target Capture</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-syslog-target-capture/m-p/4703708#M577775</link>
      <description>&lt;P data-source-line="1152"&gt;Covered in one of our &lt;A href="https://cs.co/ise-webinars" target="_self"&gt;ISE Webinars&lt;/A&gt;. Now available in the &lt;A href="https://cs.co/ise-youtube" target="_self"&gt;CiscoISE YouTube Channel&lt;/A&gt;.&lt;/P&gt;
&lt;P data-source-line="1152"&gt;&lt;STRONG&gt;▶ &lt;A class="" title="https://youtu.be/Y6F6XCLYUWA" href="https://youtu.be/Y6F6XCLYUWA" data-from-md="" target="_blank"&gt;ISE Initial Setup and Operations&lt;/A&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P data-source-line="1166"&gt;&lt;STRONG&gt;&lt;A title="https://youtu.be/Y6F6XCLYUWA&amp;amp;t=720s" href="https://youtu.be/Y6F6XCLYUWA&amp;amp;t=720s" data-from-md="" target="_blank"&gt;12:00&lt;/A&gt;&lt;/STRONG&gt; Syslogs and Remote Logging Targets&lt;BR /&gt;&lt;STRONG&gt;&lt;A title="https://youtu.be/Y6F6XCLYUWA&amp;amp;t=909s" href="https://youtu.be/Y6F6XCLYUWA&amp;amp;t=909s" data-from-md="" target="_blank"&gt;15:09&lt;/A&gt;&lt;/STRONG&gt; Logging Categories and Example Syslogs&lt;BR /&gt;&lt;STRONG&gt;&lt;A title="https://youtu.be/Y6F6XCLYUWA&amp;amp;t=1025s" href="https://youtu.be/Y6F6XCLYUWA&amp;amp;t=1025s" data-from-md="" target="_blank"&gt;17:05&lt;/A&gt;&lt;/STRONG&gt; Authentication Syslogs from Meraki Dashboard&lt;BR /&gt;&lt;STRONG&gt;&lt;A class="" title="https://youtu.be/Y6F6XCLYUWA&amp;amp;t=1173s" href="https://youtu.be/Y6F6XCLYUWA&amp;amp;t=1173s" data-from-md="" target="_blank"&gt;19:33&lt;/A&gt;&lt;/STRONG&gt; Syslog Message Catalog and Export&lt;BR /&gt;&lt;STRONG&gt;&lt;A title="https://youtu.be/Y6F6XCLYUWA&amp;amp;t=1237s" href="https://youtu.be/Y6F6XCLYUWA&amp;amp;t=1237s" data-from-md="" target="_blank"&gt;20:37&lt;/A&gt;&lt;/STRONG&gt; Syslog Collection Filters&lt;/P&gt;</description>
      <pubDate>Sat, 15 Oct 2022 14:11:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-syslog-target-capture/m-p/4703708#M577775</guid>
      <dc:creator>thomas</dc:creator>
      <dc:date>2022-10-15T14:11:11Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE Syslog Target Capture</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-syslog-target-capture/m-p/4703718#M577776</link>
      <description>&lt;P&gt;I'm thinking something is up with QRadar not showing the "Notice" syslogs. I have my logging categories setup correctly but I'm looking to see the authentication/authorization logs from every attempt. The goal is to have it so I can trigger an alert if a device is Anomalous or if it hits an Authorization Policy I set for quarantine. I saw in the documentation with QRadar they support versions 1.1 to 2.2 which I find it pretty dated. Maybe they don't accept all syslogs from ISE since I'm running 3.1P3.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 15 Oct 2022 15:17:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-syslog-target-capture/m-p/4703718#M577776</guid>
      <dc:creator>Lucas Borza</dc:creator>
      <dc:date>2022-10-15T15:17:36Z</dc:date>
    </item>
  </channel>
</rss>

