<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to work with ISE log files in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/how-to-work-with-ise-log-files/m-p/5035423#M587947</link>
    <description>&lt;P&gt;This is where the SIEM will come handy, set up the SIEM as the remote logging target.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;In Cisco ISE, choose&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Administration &amp;gt; System &amp;gt; Logging &amp;gt; Remote Logging Targets &lt;/STRONG&gt;and&lt;STRONG&gt; Add Target.&amp;nbsp;&lt;/STRONG&gt;And then you can select the categorises that you need.&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;FONT face="times new roman,times"&gt;&lt;SPAN&gt;AAA Audit&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/LI&gt;&lt;LI&gt;&lt;FONT face="times new roman,times"&gt;&lt;SPAN&gt;Failed Attempts&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV class=""&gt;&lt;FONT face="times new roman,times"&gt;Passed Authentications&lt;/FONT&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV class=""&gt;&lt;FONT face="times new roman,times"&gt;AAA Diagnostics&lt;/FONT&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV class=""&gt;&lt;FONT face="times new roman,times"&gt;Accounting&lt;/FONT&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV class=""&gt;&lt;FONT face="times new roman,times"&gt;RADIUS Accounting&lt;/FONT&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV class=""&gt;&lt;FONT face="times new roman,times"&gt;Administrative and Operational Audit&lt;/FONT&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV class=""&gt;&lt;FONT face="times new roman,times"&gt;Posture and Client Provisioning Audit&lt;/FONT&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV class=""&gt;&lt;FONT face="times new roman,times"&gt;Posture and Client Provisioning Diagnostics&lt;/FONT&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV class=""&gt;&lt;FONT face="times new roman,times"&gt;MDM&lt;/FONT&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV class=""&gt;&lt;FONT face="times new roman,times"&gt;Profiler&lt;/FONT&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV class=""&gt;&lt;FONT face="times new roman,times"&gt;System Diagnostics&lt;/FONT&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV class=""&gt;&lt;FONT face="times new roman,times"&gt;System Statistics&lt;BR /&gt;&lt;/FONT&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;FONT size="2"&gt;&lt;EM&gt;&lt;STRONG&gt;&lt;FONT face="times new roman,times"&gt;If you find this solution useful, please mark it helpful &amp;amp; accept the solution.&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 06 Mar 2024 23:53:10 GMT</pubDate>
    <dc:creator>Pulkit Mittal</dc:creator>
    <dc:date>2024-03-06T23:53:10Z</dc:date>
    <item>
      <title>How to work with ISE log files</title>
      <link>https://community.cisco.com/t5/network-access-control/how-to-work-with-ise-log-files/m-p/5035421#M587946</link>
      <description>&lt;P&gt;Hi all!&lt;/P&gt;&lt;P&gt;I am looking for some guidance on the best way to offload local logs from ISE to an SFTP location.&amp;nbsp; &amp;nbsp; For instance, I can see the localstore log via the command below.&lt;/P&gt;&lt;P&gt;ISE_PAN/admin# show logging application | inc localStore&lt;BR /&gt;5177204 Mar 06 2024 20:36:33 localStore/iseLocalStore.log&lt;/P&gt;&lt;P&gt;How do I reference that log file if I want to export it to an SFTP server?&amp;nbsp; &amp;nbsp;I know you can export the logs via the GUI but I'm looking for a quick way to get direct access to the log file so that it can be parsed/processed/analyzed.&amp;nbsp; &amp;nbsp;I'm looking for different ways to get alerted to suspicious activity such as someone logging into the environment using the local admin account often or many unsuccessful ssh/https login attempts etc.&amp;nbsp; &amp;nbsp;I know in some cases I'll be working with the alarms that are built into the administrative area of the GUI, but I also just wanted to be more familiar with how to work with the log files themselves.&lt;/P&gt;&lt;P&gt;Thanks for any advice!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Mar 2024 23:38:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-to-work-with-ise-log-files/m-p/5035421#M587946</guid>
      <dc:creator>Mr. Bash</dc:creator>
      <dc:date>2024-03-06T23:38:59Z</dc:date>
    </item>
    <item>
      <title>Re: How to work with ISE log files</title>
      <link>https://community.cisco.com/t5/network-access-control/how-to-work-with-ise-log-files/m-p/5035423#M587947</link>
      <description>&lt;P&gt;This is where the SIEM will come handy, set up the SIEM as the remote logging target.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;In Cisco ISE, choose&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Administration &amp;gt; System &amp;gt; Logging &amp;gt; Remote Logging Targets &lt;/STRONG&gt;and&lt;STRONG&gt; Add Target.&amp;nbsp;&lt;/STRONG&gt;And then you can select the categorises that you need.&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;FONT face="times new roman,times"&gt;&lt;SPAN&gt;AAA Audit&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/LI&gt;&lt;LI&gt;&lt;FONT face="times new roman,times"&gt;&lt;SPAN&gt;Failed Attempts&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV class=""&gt;&lt;FONT face="times new roman,times"&gt;Passed Authentications&lt;/FONT&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV class=""&gt;&lt;FONT face="times new roman,times"&gt;AAA Diagnostics&lt;/FONT&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV class=""&gt;&lt;FONT face="times new roman,times"&gt;Accounting&lt;/FONT&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV class=""&gt;&lt;FONT face="times new roman,times"&gt;RADIUS Accounting&lt;/FONT&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV class=""&gt;&lt;FONT face="times new roman,times"&gt;Administrative and Operational Audit&lt;/FONT&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV class=""&gt;&lt;FONT face="times new roman,times"&gt;Posture and Client Provisioning Audit&lt;/FONT&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV class=""&gt;&lt;FONT face="times new roman,times"&gt;Posture and Client Provisioning Diagnostics&lt;/FONT&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV class=""&gt;&lt;FONT face="times new roman,times"&gt;MDM&lt;/FONT&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV class=""&gt;&lt;FONT face="times new roman,times"&gt;Profiler&lt;/FONT&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV class=""&gt;&lt;FONT face="times new roman,times"&gt;System Diagnostics&lt;/FONT&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV class=""&gt;&lt;FONT face="times new roman,times"&gt;System Statistics&lt;BR /&gt;&lt;/FONT&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;FONT size="2"&gt;&lt;EM&gt;&lt;STRONG&gt;&lt;FONT face="times new roman,times"&gt;If you find this solution useful, please mark it helpful &amp;amp; accept the solution.&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Mar 2024 23:53:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-to-work-with-ise-log-files/m-p/5035423#M587947</guid>
      <dc:creator>Pulkit Mittal</dc:creator>
      <dc:date>2024-03-06T23:53:10Z</dc:date>
    </item>
  </channel>
</rss>

