<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Log analytics with elk for monitoring reports in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/log-analytics-with-elk-for-monitoring-reports/m-p/5055033#M588547</link>
    <description>&lt;P&gt;Stay away from Splunk.&amp;nbsp; It is an overprice product.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ElasticSearch is a good product, free because it is an opensource.&amp;nbsp; You can purchase support if needed, so much cheaper than Splunk.&amp;nbsp; Elastic Search is also running in Cisco ISE.&amp;nbsp; If it is good enough for Cisco, it is good enough for most enterprise environment.&amp;nbsp; Very easily deployed in AWS.&lt;/P&gt;</description>
    <pubDate>Tue, 02 Apr 2024 20:19:03 GMT</pubDate>
    <dc:creator>adamscottmaster2013</dc:creator>
    <dc:date>2024-04-02T20:19:03Z</dc:date>
    <item>
      <title>Log analytics with elk for monitoring reports</title>
      <link>https://community.cisco.com/t5/network-access-control/log-analytics-with-elk-for-monitoring-reports/m-p/5054068#M588512</link>
      <description>&lt;P&gt;In Ise version 3.3 there is a feature of&amp;nbsp;System 360 that includes Monitoring and Log Analytics, with elk monitoring , I want to fetch the radius accounting logs for the last 90 days.&amp;nbsp; Will this feature be able to fetch logs of last 90 days and if not , then logs of how many days can be retrieved using this feature?&lt;/P&gt;</description>
      <pubDate>Mon, 01 Apr 2024 06:21:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/log-analytics-with-elk-for-monitoring-reports/m-p/5054068#M588512</guid>
      <dc:creator>jagritibhardwaj471</dc:creator>
      <dc:date>2024-04-01T06:21:04Z</dc:date>
    </item>
    <item>
      <title>Re: Log analytics with elk for monitoring reports</title>
      <link>https://community.cisco.com/t5/network-access-control/log-analytics-with-elk-for-monitoring-reports/m-p/5054152#M588515</link>
      <description>&lt;P&gt;As per the i know ISE 3.3 Log analytics - how the system performing -&amp;nbsp;check the admin guide -&amp;nbsp;&lt;STRONG&gt;System 360&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;check the data retained as mentioned in the document.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/3-3/admin_guide/b_ise_admin_3_3/b_ISE_admin_33_maintain_monitor.html#c_system360" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/ise/3-3/admin_guide/b_ise_admin_3_3/b_ISE_admin_33_maintain_monitor.html#c_system360&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 01 Apr 2024 10:02:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/log-analytics-with-elk-for-monitoring-reports/m-p/5054152#M588515</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2024-04-01T10:02:45Z</dc:date>
    </item>
    <item>
      <title>Re: Log analytics with elk for monitoring reports</title>
      <link>https://community.cisco.com/t5/network-access-control/log-analytics-with-elk-for-monitoring-reports/m-p/5054170#M588516</link>
      <description>&lt;P&gt;No, log analytics only has a 7 day retention time.&lt;/P&gt;</description>
      <pubDate>Mon, 01 Apr 2024 11:15:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/log-analytics-with-elk-for-monitoring-reports/m-p/5054170#M588516</guid>
      <dc:creator>ahollifield</dc:creator>
      <dc:date>2024-04-01T11:15:41Z</dc:date>
    </item>
    <item>
      <title>Re: Log analytics with elk for monitoring reports</title>
      <link>https://community.cisco.com/t5/network-access-control/log-analytics-with-elk-for-monitoring-reports/m-p/5054562#M588524</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1703884"&gt;@jagritibhardwaj471&lt;/a&gt;&amp;nbsp;- I was also surprised to learn that Log Analytics only retains 7 days (I guess I should read that link in more detail) - perhaps the answer lies in the Data Connect feature (ODBC/JDBC) to fetch data from the MNTs using SQL queries.&lt;/P&gt;
&lt;P&gt;Administration &amp;gt; System &amp;gt; Data Connect&lt;/P&gt;
&lt;P&gt;There are SQL tools like &lt;A href="https://squirrel-sql.sourceforge.io/" target="_blank"&gt;SQuirreL SQL Client Home Page (sourceforge.io)&lt;/A&gt;&amp;nbsp;or&amp;nbsp;&lt;A href="https://learn.microsoft.com/en-us/sql/ssms/download-sql-server-management-studio-ssms?view=sql-server-ver16" target="_blank"&gt;Download SQL Server Management Studio (SSMS) - SQL Server Management Studio (SSMS) | Microsoft Learn&lt;/A&gt;&amp;nbsp;to visually inspect and fetch data from the ISE database when Data Connect is enabled.&lt;/P&gt;</description>
      <pubDate>Mon, 01 Apr 2024 20:52:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/log-analytics-with-elk-for-monitoring-reports/m-p/5054562#M588524</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2024-04-01T20:52:17Z</dc:date>
    </item>
    <item>
      <title>Re: Log analytics with elk for monitoring reports</title>
      <link>https://community.cisco.com/t5/network-access-control/log-analytics-with-elk-for-monitoring-reports/m-p/5054650#M588528</link>
      <description>&lt;P&gt;That means the only way to collect last 90 days radius accounting logs is via data connect ?? But in my case , we are working with Ise release 2.7 and data connect is a feature for versions starting from release 3.2 . Does that conclude that we have no other way to collect historic radius accounting logs apart from data connect ?&lt;/P&gt;</description>
      <pubDate>Tue, 02 Apr 2024 04:38:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/log-analytics-with-elk-for-monitoring-reports/m-p/5054650#M588528</guid>
      <dc:creator>jagritibhardwaj471</dc:creator>
      <dc:date>2024-04-02T04:38:46Z</dc:date>
    </item>
    <item>
      <title>Re: Log analytics with elk for monitoring reports</title>
      <link>https://community.cisco.com/t5/network-access-control/log-analytics-with-elk-for-monitoring-reports/m-p/5054863#M588536</link>
      <description>&amp;lt;&amp;gt;&lt;BR /&gt;[logo-open-graph.gif]&lt;BR /&gt;Cisco Identity Services Engine 2.7 - End of Life Announcement for the Cisco Identity Services Engine Software Version 2.7&amp;lt;&amp;gt;&lt;BR /&gt;cisco.com&amp;lt;&amp;gt;&lt;BR /&gt;What is your use-case for needing 90 days of accounting logs? Why not use a Syslog collector instead?&lt;BR /&gt;</description>
      <pubDate>Tue, 02 Apr 2024 10:35:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/log-analytics-with-elk-for-monitoring-reports/m-p/5054863#M588536</guid>
      <dc:creator>ahollifield</dc:creator>
      <dc:date>2024-04-02T10:35:57Z</dc:date>
    </item>
    <item>
      <title>Re: Log analytics with elk for monitoring reports</title>
      <link>https://community.cisco.com/t5/network-access-control/log-analytics-with-elk-for-monitoring-reports/m-p/5054914#M588540</link>
      <description>&lt;P&gt;Actually my purpose is to collect the radius accounting logs of last 90 days&amp;nbsp; , we have to generate reports according to that .&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 02 Apr 2024 11:43:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/log-analytics-with-elk-for-monitoring-reports/m-p/5054914#M588540</guid>
      <dc:creator>jagritibhardwaj471</dc:creator>
      <dc:date>2024-04-02T11:43:00Z</dc:date>
    </item>
    <item>
      <title>Re: Log analytics with elk for monitoring reports</title>
      <link>https://community.cisco.com/t5/network-access-control/log-analytics-with-elk-for-monitoring-reports/m-p/5054942#M588542</link>
      <description>&lt;P&gt;Why?&amp;nbsp; What value would RADIUS accounting give you?&amp;nbsp; What exactly are you looking for in the accounting logs?&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/products/collateral/security/identity-services-engine/bulletin-c25-2943876.html" target="_blank"&gt;https://www.cisco.com/c/en/us/products/collateral/security/identity-services-engine/bulletin-c25-2943876.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 02 Apr 2024 12:15:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/log-analytics-with-elk-for-monitoring-reports/m-p/5054942#M588542</guid>
      <dc:creator>ahollifield</dc:creator>
      <dc:date>2024-04-02T12:15:39Z</dc:date>
    </item>
    <item>
      <title>Re: Log analytics with elk for monitoring reports</title>
      <link>https://community.cisco.com/t5/network-access-control/log-analytics-with-elk-for-monitoring-reports/m-p/5054949#M588544</link>
      <description>&lt;P&gt;My bad I was actually looking to get radius authentication logs and not radius accounting logs.&lt;/P&gt;</description>
      <pubDate>Tue, 02 Apr 2024 12:18:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/log-analytics-with-elk-for-monitoring-reports/m-p/5054949#M588544</guid>
      <dc:creator>jagritibhardwaj471</dc:creator>
      <dc:date>2024-04-02T12:18:20Z</dc:date>
    </item>
    <item>
      <title>Re: Log analytics with elk for monitoring reports</title>
      <link>https://community.cisco.com/t5/network-access-control/log-analytics-with-elk-for-monitoring-reports/m-p/5054999#M588546</link>
      <description>Got it, this is where you should be sending Syslogs to an external Syslog server. ISE isn’t necessarily designed for long term data collection, reporting, correlation, etc this would be the job of a product such as Splunk or a SIEM. &lt;BR /&gt;</description>
      <pubDate>Tue, 02 Apr 2024 12:52:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/log-analytics-with-elk-for-monitoring-reports/m-p/5054999#M588546</guid>
      <dc:creator>ahollifield</dc:creator>
      <dc:date>2024-04-02T12:52:57Z</dc:date>
    </item>
    <item>
      <title>Re: Log analytics with elk for monitoring reports</title>
      <link>https://community.cisco.com/t5/network-access-control/log-analytics-with-elk-for-monitoring-reports/m-p/5055033#M588547</link>
      <description>&lt;P&gt;Stay away from Splunk.&amp;nbsp; It is an overprice product.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ElasticSearch is a good product, free because it is an opensource.&amp;nbsp; You can purchase support if needed, so much cheaper than Splunk.&amp;nbsp; Elastic Search is also running in Cisco ISE.&amp;nbsp; If it is good enough for Cisco, it is good enough for most enterprise environment.&amp;nbsp; Very easily deployed in AWS.&lt;/P&gt;</description>
      <pubDate>Tue, 02 Apr 2024 20:19:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/log-analytics-with-elk-for-monitoring-reports/m-p/5055033#M588547</guid>
      <dc:creator>adamscottmaster2013</dc:creator>
      <dc:date>2024-04-02T20:19:03Z</dc:date>
    </item>
  </channel>
</rss>

