<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco ISE - Remote target logging SIEM in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-ise-remote-target-logging-siem/m-p/4957641#M585148</link>
    <description>&lt;P&gt;When configured with a remote logging target, all ISE nodes will directly send syslog to the external target. The PSNs will send endpoint session-related logs directly to the target and all nodes will send health-related logs directly to the target.&lt;/P&gt;</description>
    <pubDate>Sun, 12 Nov 2023 23:28:28 GMT</pubDate>
    <dc:creator>Greg Gibbs</dc:creator>
    <dc:date>2023-11-12T23:28:28Z</dc:date>
    <item>
      <title>Cisco ISE - Remote target logging SIEM</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-remote-target-logging-siem/m-p/4957625#M585142</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;&lt;BR /&gt;I need to integrate ISE to send logs to SIEM.&lt;BR /&gt;I have a distributed large deployment, one VM for each ISE persona.&lt;BR /&gt;&lt;BR /&gt;My doubt is the following:&lt;BR /&gt;1. Which IP address should I configure on SIEM? &lt;STRONG&gt;Only MnT nodes&lt;/STRONG&gt;? or all Cisco ISE nodes?&lt;/P&gt;&lt;P&gt;2. Which ISE node will send logs to SIEM?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 12 Nov 2023 22:01:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-remote-target-logging-siem/m-p/4957625#M585142</guid>
      <dc:creator>iran</dc:creator>
      <dc:date>2023-11-12T22:01:16Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE - Remote target logging SIEM</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-remote-target-logging-siem/m-p/4957641#M585148</link>
      <description>&lt;P&gt;When configured with a remote logging target, all ISE nodes will directly send syslog to the external target. The PSNs will send endpoint session-related logs directly to the target and all nodes will send health-related logs directly to the target.&lt;/P&gt;</description>
      <pubDate>Sun, 12 Nov 2023 23:28:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-remote-target-logging-siem/m-p/4957641#M585148</guid>
      <dc:creator>Greg Gibbs</dc:creator>
      <dc:date>2023-11-12T23:28:28Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE - Remote target logging SIEM</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-remote-target-logging-siem/m-p/4958287#M585161</link>
      <description>&lt;P&gt;Hello, Thank you.&lt;BR /&gt;&lt;BR /&gt;I am still with doubts about which IP addresses should I add on SIEM server configuration and allow firewall rules.&lt;BR /&gt;&lt;BR /&gt;My initial understanding was that there is only need to add &lt;STRONG&gt;MnT IP addresses&lt;/STRONG&gt; on SIEM configuration. Please, let me know if this is not correct.&lt;BR /&gt;&lt;BR /&gt;Since all the logs are sent to MnT, I am assuming that MnT has the needed information to send to the SIEM&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 13 Nov 2023 15:10:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-remote-target-logging-siem/m-p/4958287#M585161</guid>
      <dc:creator>iran</dc:creator>
      <dc:date>2023-11-13T15:10:05Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE - Remote target logging SIEM</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-remote-target-logging-siem/m-p/4958338#M585162</link>
      <description>&lt;P&gt;I use splunk as remoting logging target and configure all ISE nodes to communicate with splunk SIEM.&lt;/P&gt;</description>
      <pubDate>Mon, 13 Nov 2023 16:25:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-remote-target-logging-siem/m-p/4958338#M585162</guid>
      <dc:creator>adamscottmaster2013</dc:creator>
      <dc:date>2023-11-13T16:25:02Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE - Remote target logging SIEM</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-remote-target-logging-siem/m-p/4958360#M585165</link>
      <description>&lt;P&gt;That is the case unless you configure an external logging target. When you configure the external logging target all ISE nodes that would have generated and sent the logs to the MnT will start sending their logs to the external logging target.&lt;/P&gt;</description>
      <pubDate>Mon, 13 Nov 2023 17:12:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-remote-target-logging-siem/m-p/4958360#M585165</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2023-11-13T17:12:15Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE - Remote target logging SIEM</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-remote-target-logging-siem/m-p/4958495#M585166</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1051287"&gt;@iran &lt;/a&gt;&amp;nbsp;... to be very clear, the MnT nodes DO NOT 'roll-up' logs sent from the other nodes and send them to the external syslog/SIEM server. As I stated before, all nodes will source their relevant syslog messages directly to the external target.&lt;/P&gt;</description>
      <pubDate>Mon, 13 Nov 2023 21:10:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-remote-target-logging-siem/m-p/4958495#M585166</guid>
      <dc:creator>Greg Gibbs</dc:creator>
      <dc:date>2023-11-13T21:10:31Z</dc:date>
    </item>
  </channel>
</rss>

