<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco ISE kibana alert after applying 3.2 patch 7 in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-ise-kibana-alert-after-applying-3-2-patch-7/m-p/5251214#M594417</link>
    <description>&lt;P&gt;I ended up getting TAC involved to fix this.&amp;nbsp; The problem was a duplicate entry in the hosts file for the host itself (!!).&lt;/P&gt;&lt;P&gt;After the engineer got in via a root shell and removed the duplicate line from /etc/hosts the service was able to start and the alert emails have stopped.&lt;/P&gt;</description>
    <pubDate>Wed, 22 Jan 2025 21:50:50 GMT</pubDate>
    <dc:creator>b__k</dc:creator>
    <dc:date>2025-01-22T21:50:50Z</dc:date>
    <item>
      <title>Cisco ISE kibana alert after applying 3.2 patch 7</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-kibana-alert-after-applying-3-2-patch-7/m-p/5249787#M594334</link>
      <description>&lt;P&gt;Recently we recently applied patch 7 to ISE 3.2 to mitigate the issue noted in Field Notice FN74227&lt;/P&gt;&lt;P&gt;Since then I'm receiving alerts about the kibana service not running.&amp;nbsp; As far as I'm aware it was disabled before applying the patch, same as on another ISE instance I'm yet to patch.&amp;nbsp; Show application status of the unpatched (patch 4) ISE instance:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;ISE PROCESS NAME                       STATE            PROCESS ID  
--------------------------------------------------------------------
ISE MNT LogAnalytics Elasticsearch     disabled                     
ISE Logstash Service                   disabled                     
ISE Kibana Service                     disabled  &lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;show application status of the patched ISE:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;ISE PROCESS NAME                       STATE            PROCESS ID  
--------------------------------------------------------------------
ISE MNT LogAnalytics Elasticsearch     running          306097      
ISE Logstash Service                   running          309335      
ISE Kibana Service                     not running                &lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How do I disable these services again?&lt;/P&gt;</description>
      <pubDate>Tue, 21 Jan 2025 00:26:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-kibana-alert-after-applying-3-2-patch-7/m-p/5249787#M594334</guid>
      <dc:creator>b__k</dc:creator>
      <dc:date>2025-01-21T00:26:33Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE kibana alert after applying 3.2 patch 7</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-kibana-alert-after-applying-3-2-patch-7/m-p/5249868#M594340</link>
      <description>&lt;P&gt;Disable the Log Analytics feature -&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/3-2/admin_guide/b_ise_admin_3_2/b_ISE_admin_33_maintain_monitor.html?bookSearch=true#Cisco_Concept.dita_6903790d-f80e-49e0-9ee8-ce2a1b9c5f74" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/ise/3-2/admin_guide/b_ise_admin_3_2/b_ISE_admin_33_maintain_monitor.html?bookSearch=true#Cisco_Concept.dita_6903790d-f80e-49e0-9ee8-ce2a1b9c5f74&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Jan 2025 05:29:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-kibana-alert-after-applying-3-2-patch-7/m-p/5249868#M594340</guid>
      <dc:creator>Greg Gibbs</dc:creator>
      <dc:date>2025-01-21T05:29:34Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE kibana alert after applying 3.2 patch 7</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-kibana-alert-after-applying-3-2-patch-7/m-p/5250500#M594383</link>
      <description>&lt;P&gt;That was showing as already disabled.&amp;nbsp; Nevertheless, I toggled it on/off, however after clicking save the UI sat there for a long time before returning a http-get error.&lt;/P&gt;&lt;P&gt;I also tried a stop/start of the ISE application on the secondary node but it still tried to start the ELK stack:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;Starting ISE MNT LogAnalytics Elasticsearch Service...
Starting ISE Logstash Service...
Starting ISE Kibana Service...
 ise-kibana-container failed to start ...&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Jan 2025 22:39:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-kibana-alert-after-applying-3-2-patch-7/m-p/5250500#M594383</guid>
      <dc:creator>b__k</dc:creator>
      <dc:date>2025-01-21T22:39:12Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE kibana alert after applying 3.2 patch 7</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-kibana-alert-after-applying-3-2-patch-7/m-p/5251214#M594417</link>
      <description>&lt;P&gt;I ended up getting TAC involved to fix this.&amp;nbsp; The problem was a duplicate entry in the hosts file for the host itself (!!).&lt;/P&gt;&lt;P&gt;After the engineer got in via a root shell and removed the duplicate line from /etc/hosts the service was able to start and the alert emails have stopped.&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jan 2025 21:50:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-kibana-alert-after-applying-3-2-patch-7/m-p/5251214#M594417</guid>
      <dc:creator>b__k</dc:creator>
      <dc:date>2025-01-22T21:50:50Z</dc:date>
    </item>
  </channel>
</rss>

