<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE(TACACS) log categories to send NADs audit trail to remote targ in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-tacacs-log-categories-to-send-nads-audit-trail-to-remote/m-p/4972651#M585566</link>
    <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/293790"&gt;@Andrii Oliinyk&lt;/a&gt;:&amp;nbsp; you might not to worry about if you use TCP syslog but I am not so sure about this.&amp;nbsp; I only use udp syslog and that's what I observed.&lt;/P&gt;</description>
    <pubDate>Wed, 06 Dec 2023 20:23:10 GMT</pubDate>
    <dc:creator>adamscottmaster2013</dc:creator>
    <dc:date>2023-12-06T20:23:10Z</dc:date>
    <item>
      <title>ISE(TACACS) log categories to send NADs audit trail to remote targets</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-tacacs-log-categories-to-send-nads-audit-trail-to-remote/m-p/4971799#M585543</link>
      <description>&lt;P&gt;Hi Guys&lt;BR /&gt;unsuccessfully have been searching through docs to discover.&lt;BR /&gt;Can it be Accounting /&amp;nbsp;TACACS Accounting or ...?&lt;/P&gt;
&lt;P&gt;Any help please&lt;/P&gt;</description>
      <pubDate>Tue, 05 Dec 2023 15:53:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-tacacs-log-categories-to-send-nads-audit-trail-to-remote/m-p/4971799#M585543</guid>
      <dc:creator>Andrii Oliinyk</dc:creator>
      <dc:date>2023-12-05T15:53:43Z</dc:date>
    </item>
    <item>
      <title>Re: ISE(TACACS) log categories to send NADs audit trail to remote targ</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-tacacs-log-categories-to-send-nads-audit-trail-to-remote/m-p/4971951#M585544</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/293790"&gt;@Andrii Oliinyk&lt;/a&gt;:&amp;nbsp; can you elaborate exactly what you're trying to do so that I might be able to help you?&lt;/P&gt;</description>
      <pubDate>Tue, 05 Dec 2023 21:00:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-tacacs-log-categories-to-send-nads-audit-trail-to-remote/m-p/4971951#M585544</guid>
      <dc:creator>adamscottmaster2013</dc:creator>
      <dc:date>2023-12-05T21:00:21Z</dc:date>
    </item>
    <item>
      <title>Re: ISE(TACACS) log categories to send NADs audit trail to remote targ</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-tacacs-log-categories-to-send-nads-audit-trail-to-remote/m-p/4972165#M585551</link>
      <description>&lt;P&gt;Hi Adam&lt;BR /&gt;DNAC-managed devices are configured with below aaa (meaning whatever network admin activity on the switch happens it gets sent to TACACS)&lt;BR /&gt;aaa authentication login default group tacacs+ local&lt;BR /&gt;aaa authentication enable default group tacacs+ enable&lt;BR /&gt;aaa authorization exec default group tacacs+ local if-authenticated&lt;BR /&gt;aaa authorization commands 15 default group tacacs+ if-authenticated&lt;BR /&gt;aaa accounting exec default start-stop group tacacs+&lt;BR /&gt;aaa accounting commands 1 default start-stop group tacacs+&lt;BR /&gt;aaa accounting commands 15 default start-stop group tacacs+&lt;BR /&gt;Now, in the ISE, we want all this events to be sent to remote SYSLOG-server.&lt;BR /&gt;What would be appropriate ISE logging category to address this topic?&lt;BR /&gt;Within my assumptions r :&lt;BR /&gt;AAA Diagnostics / TACACS Diagnostics&lt;BR /&gt;Accounting /&amp;nbsp;TACACS Accounting&lt;/P&gt;
&lt;P&gt;Can u confirm? Does it fully address requirement?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Dec 2023 08:34:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-tacacs-log-categories-to-send-nads-audit-trail-to-remote/m-p/4972165#M585551</guid>
      <dc:creator>Andrii Oliinyk</dc:creator>
      <dc:date>2023-12-06T08:34:04Z</dc:date>
    </item>
    <item>
      <title>Re: ISE(TACACS) log categories to send NADs audit trail to remote targ</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-tacacs-log-categories-to-send-nads-audit-trail-to-remote/m-p/4972320#M585554</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/293790"&gt;@Andrii Oliinyk&lt;/a&gt;:&amp;nbsp; Yes, you are correct but you do not need&amp;nbsp;&lt;SPAN&gt;AAA Diagnostics / TACACS Diagnostics.&amp;nbsp; What you do is to create a new syslog collector and add add under the Accounting remote target.&amp;nbsp; One other thing, make sure you change that syslog collector size limit to 8192 to avoid your AAA accounting log being cutoff.&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;HTH.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Dec 2023 12:19:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-tacacs-log-categories-to-send-nads-audit-trail-to-remote/m-p/4972320#M585554</guid>
      <dc:creator>adamscottmaster2013</dc:creator>
      <dc:date>2023-12-06T12:19:35Z</dc:date>
    </item>
    <item>
      <title>Re: ISE(TACACS) log categories to send NADs audit trail to remote targ</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-tacacs-log-categories-to-send-nads-audit-trail-to-remote/m-p/4972519#M585560</link>
      <description>&lt;P&gt;Hi Adam&lt;BR /&gt;thanks for input. could you please bring more details on collector size (Maximum Length, right?) limit as it seems to&amp;nbsp;be smaller atm&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="andydoesntlikeuucp_0-1701879464678.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/204215iB20B5EBEC94FAA5A/image-size/medium?v=v2&amp;amp;px=400" role="button" title="andydoesntlikeuucp_0-1701879464678.png" alt="andydoesntlikeuucp_0-1701879464678.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Dec 2023 16:18:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-tacacs-log-categories-to-send-nads-audit-trail-to-remote/m-p/4972519#M585560</guid>
      <dc:creator>Andrii Oliinyk</dc:creator>
      <dc:date>2023-12-06T16:18:53Z</dc:date>
    </item>
    <item>
      <title>Re: ISE(TACACS) log categories to send NADs audit trail to remote targ</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-tacacs-log-categories-to-send-nads-audit-trail-to-remote/m-p/4972558#M585563</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/293790"&gt;@Andrii Oliinyk&lt;/a&gt;:&amp;nbsp; The default value of 1024 might not be enough for some of the AAA accounting message because some of them might get truncated.&amp;nbsp; Maximum length 8192 should be used whenever possible.&lt;/P&gt;</description>
      <pubDate>Wed, 06 Dec 2023 17:25:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-tacacs-log-categories-to-send-nads-audit-trail-to-remote/m-p/4972558#M585563</guid>
      <dc:creator>adamscottmaster2013</dc:creator>
      <dc:date>2023-12-06T17:25:18Z</dc:date>
    </item>
    <item>
      <title>Re: ISE(TACACS) log categories to send NADs audit trail to remote targ</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-tacacs-log-categories-to-send-nads-audit-trail-to-remote/m-p/4972607#M585565</link>
      <description>&lt;P&gt;does it mean that TACACS's syslog agent truncates message on its level of operation? bc we have TCP syslog which must manage this stuff with TCP MSS payload adjustment on the transport layer.&lt;/P&gt;</description>
      <pubDate>Wed, 06 Dec 2023 18:45:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-tacacs-log-categories-to-send-nads-audit-trail-to-remote/m-p/4972607#M585565</guid>
      <dc:creator>Andrii Oliinyk</dc:creator>
      <dc:date>2023-12-06T18:45:01Z</dc:date>
    </item>
    <item>
      <title>Re: ISE(TACACS) log categories to send NADs audit trail to remote targ</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-tacacs-log-categories-to-send-nads-audit-trail-to-remote/m-p/4972651#M585566</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/293790"&gt;@Andrii Oliinyk&lt;/a&gt;:&amp;nbsp; you might not to worry about if you use TCP syslog but I am not so sure about this.&amp;nbsp; I only use udp syslog and that's what I observed.&lt;/P&gt;</description>
      <pubDate>Wed, 06 Dec 2023 20:23:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-tacacs-log-categories-to-send-nads-audit-trail-to-remote/m-p/4972651#M585566</guid>
      <dc:creator>adamscottmaster2013</dc:creator>
      <dc:date>2023-12-06T20:23:10Z</dc:date>
    </item>
    <item>
      <title>Re: ISE(TACACS) log categories to send NADs audit trail to remote targ</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-tacacs-log-categories-to-send-nads-audit-trail-to-remote/m-p/4972662#M585568</link>
      <description>&lt;P&gt;good to know it's not n application layer defect as well as good syslog implementation could be reliable even with udp :0)&amp;nbsp; &amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Dec 2023 20:45:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-tacacs-log-categories-to-send-nads-audit-trail-to-remote/m-p/4972662#M585568</guid>
      <dc:creator>Andrii Oliinyk</dc:creator>
      <dc:date>2023-12-06T20:45:12Z</dc:date>
    </item>
  </channel>
</rss>

