<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: syslog CISE_Alarm vs CISE_Administrative_and_Operational_Audit in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/syslog-cise-alarm-vs-cise-administrative-and-operational-audit/m-p/4852254#M582153</link>
    <description>&lt;P&gt;Impacted ISE version 2.7.0.356 (patches 3,6,7,8)&lt;BR /&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/66272"&gt;@poongarg&lt;/a&gt;&amp;nbsp; - do you think that another patch or upgrade would resolve the issue? Is there anything we can do to get the unique &lt;SPAN class=""&gt;message &lt;/SPAN&gt;codes back?&lt;BR /&gt;I am supporting 10 other deployments running on different versions, this is the only environment I am facing the bug.&lt;BR /&gt;Would be worth to open TAC for this?&lt;/P&gt;</description>
    <pubDate>Sat, 10 Jun 2023 09:42:13 GMT</pubDate>
    <dc:creator>Jemmotar</dc:creator>
    <dc:date>2023-06-10T09:42:13Z</dc:date>
    <item>
      <title>syslog CISE_Alarm vs CISE_Administrative_and_Operational_Audit</title>
      <link>https://community.cisco.com/t5/network-access-control/syslog-cise-alarm-vs-cise-administrative-and-operational-audit/m-p/4851671#M582127</link>
      <description>&lt;P&gt;Hello everyone!&lt;BR /&gt;&lt;BR /&gt;We are using syslogs for monitoring. I have multiple deployments that are very similar to each other.&lt;BR /&gt;But I just found out that one of them is different when comes to syslog messages.&lt;BR /&gt;&lt;BR /&gt;My syslog monitoring is expecting to see this message:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;Jun  2 00:00:00 hostname CISE_Administrative_and_Operational_Audit 0007666335 1 0 2023-06-02 00:00:00.323 +00:00 0741901856 60166 NOTICE Certificate: Certificate will expire soon, ConfigVersionId=442, OperationMessageText=Local certificate 'something' will expire in 60 days,&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But I get this instead:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;Jun 8 00:00:10 hostname  CISE_Alarm WARN: Local certificate 'C=US;ST=Somewhere;L=Arlington;O=The Something Corporation;CN=something.something.com#Entrust Certification Authority - L1K#000
05' will expire in 10 days : Server=something&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;I was expecting (per the cisco ise syslog list) that every syslog has its own code, why &lt;FONT face="courier new,courier"&gt;CISE_Alarm&lt;/FONT&gt; bypass that convention?&lt;BR /&gt;&lt;STRONG&gt;&lt;FONT size="4"&gt;Where to adjust this configuration please?&lt;/FONT&gt;&lt;/STRONG&gt;&lt;BR /&gt;I want all my syslogs to follow the catalog aka &lt;FONT face="courier new,courier"&gt;CISE_Administrative_and_Operational_Audit&lt;/FONT&gt; instead of &lt;FONT face="courier new,courier"&gt;CISE_Alarm&lt;/FONT&gt;.&lt;/P&gt;</description>
      <pubDate>Thu, 08 Jun 2023 23:03:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/syslog-cise-alarm-vs-cise-administrative-and-operational-audit/m-p/4851671#M582127</guid>
      <dc:creator>Jemmotar</dc:creator>
      <dc:date>2023-06-08T23:03:57Z</dc:date>
    </item>
    <item>
      <title>Re: syslog CISE_Alarm vs CISE_Administrative_and_Operational_Audit</title>
      <link>https://community.cisco.com/t5/network-access-control/syslog-cise-alarm-vs-cise-administrative-and-operational-audit/m-p/4851697#M582128</link>
      <description>&lt;P&gt;Alarm messages don't show the message code. There is an enhancement already filed for this change:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://bst.cisco.com/bugsearch/bug/CSCvw55478" target="_blank"&gt;https://bst.cisco.com/bugsearch/bug/CSCvw55478&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 09 Jun 2023 00:44:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/syslog-cise-alarm-vs-cise-administrative-and-operational-audit/m-p/4851697#M582128</guid>
      <dc:creator>poongarg</dc:creator>
      <dc:date>2023-06-09T00:44:38Z</dc:date>
    </item>
    <item>
      <title>Re: syslog CISE_Alarm vs CISE_Administrative_and_Operational_Audit</title>
      <link>https://community.cisco.com/t5/network-access-control/syslog-cise-alarm-vs-cise-administrative-and-operational-audit/m-p/4852254#M582153</link>
      <description>&lt;P&gt;Impacted ISE version 2.7.0.356 (patches 3,6,7,8)&lt;BR /&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/66272"&gt;@poongarg&lt;/a&gt;&amp;nbsp; - do you think that another patch or upgrade would resolve the issue? Is there anything we can do to get the unique &lt;SPAN class=""&gt;message &lt;/SPAN&gt;codes back?&lt;BR /&gt;I am supporting 10 other deployments running on different versions, this is the only environment I am facing the bug.&lt;BR /&gt;Would be worth to open TAC for this?&lt;/P&gt;</description>
      <pubDate>Sat, 10 Jun 2023 09:42:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/syslog-cise-alarm-vs-cise-administrative-and-operational-audit/m-p/4852254#M582153</guid>
      <dc:creator>Jemmotar</dc:creator>
      <dc:date>2023-06-10T09:42:13Z</dc:date>
    </item>
    <item>
      <title>Re: syslog CISE_Alarm vs CISE_Administrative_and_Operational_Audit</title>
      <link>https://community.cisco.com/t5/network-access-control/syslog-cise-alarm-vs-cise-administrative-and-operational-audit/m-p/4852256#M582154</link>
      <description>&lt;P&gt;I could rephrase as missing "OperationMessageText=" as part of the syslog. (I can live without the unique codes, OperationMessageText is more important for me)&lt;/P&gt;</description>
      <pubDate>Sat, 10 Jun 2023 10:12:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/syslog-cise-alarm-vs-cise-administrative-and-operational-audit/m-p/4852256#M582154</guid>
      <dc:creator>Jemmotar</dc:creator>
      <dc:date>2023-06-10T10:12:47Z</dc:date>
    </item>
    <item>
      <title>Re: syslog CISE_Alarm vs CISE_Administrative_and_Operational_Audit</title>
      <link>https://community.cisco.com/t5/network-access-control/syslog-cise-alarm-vs-cise-administrative-and-operational-audit/m-p/4852395#M582160</link>
      <description>&lt;P&gt;The enhancement is filed on top of ISE 3.1 and yet not incorporated in any release. So upgrading the patch or version will not help.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 11 Jun 2023 00:28:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/syslog-cise-alarm-vs-cise-administrative-and-operational-audit/m-p/4852395#M582160</guid>
      <dc:creator>poongarg</dc:creator>
      <dc:date>2023-06-11T00:28:58Z</dc:date>
    </item>
  </channel>
</rss>

