<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ISE and SIEM integration in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-and-siem-integration/m-p/2465087#M88242</link>
    <description>&lt;P&gt;Hi, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;One of the major concerns regarding security solutions is the way they interact. ISE specifically, is compatible with most of the SIEMs available today, as stated by Cisco (&lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/prod/vpndevc/ecosystem.html" rel="nofollow" target="_blank"&gt;http://www.cisco.com/en/US/prod/vpndevc/ecosystem.html&lt;/A&gt;&lt;SPAN&gt;). &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In my particular case, I want to integrate ISE with ArcSight. &lt;/P&gt;&lt;P&gt;For ArcSight to correctly parse the syslog messages that ISE sends, you have to install/configure an ISE smartconnector. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What I'm missing though is how does ArcSight instructs ISE to take specific actions on users/devices that are involved in a network attack.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Please check: &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/prod/collateral/vpndevc/ps5712/ps11640/at_a_glance_c45-728401.pdf" rel="nofollow" target="_blank"&gt;http://www.cisco.com/en/US/prod/collateral/vpndevc/ps5712/ps11640/at_a_glance_c45-728401.pdf&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P dir="ltr" style="font-size: 12px; font-family: sans-serif; left: 552.267px; top: 634.773px; transform: rotate(0deg) scale(1.0016, 1); transform-origin: 0% 0% 0px;"&gt;SIEM/TD partners may utilize ISE as a conduit for taking mitigation actions within the Cisco network infrastructure. SIEM/TD platforms can instruct ISE to undertake quarantine or access-block actions on users and/or device based on ISE policies that have been defined for such actions. &lt;/P&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks! &lt;/P&gt;&lt;P&gt;Octavian&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 04:22:04 GMT</pubDate>
    <dc:creator>Octavian Szolga</dc:creator>
    <dc:date>2019-03-11T04:22:04Z</dc:date>
    <item>
      <title>ISE and SIEM integration</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-and-siem-integration/m-p/2465087#M88242</link>
      <description>&lt;P&gt;Hi, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;One of the major concerns regarding security solutions is the way they interact. ISE specifically, is compatible with most of the SIEMs available today, as stated by Cisco (&lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/prod/vpndevc/ecosystem.html" rel="nofollow" target="_blank"&gt;http://www.cisco.com/en/US/prod/vpndevc/ecosystem.html&lt;/A&gt;&lt;SPAN&gt;). &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In my particular case, I want to integrate ISE with ArcSight. &lt;/P&gt;&lt;P&gt;For ArcSight to correctly parse the syslog messages that ISE sends, you have to install/configure an ISE smartconnector. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What I'm missing though is how does ArcSight instructs ISE to take specific actions on users/devices that are involved in a network attack.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Please check: &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/prod/collateral/vpndevc/ps5712/ps11640/at_a_glance_c45-728401.pdf" rel="nofollow" target="_blank"&gt;http://www.cisco.com/en/US/prod/collateral/vpndevc/ps5712/ps11640/at_a_glance_c45-728401.pdf&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P dir="ltr" style="font-size: 12px; font-family: sans-serif; left: 552.267px; top: 634.773px; transform: rotate(0deg) scale(1.0016, 1); transform-origin: 0% 0% 0px;"&gt;SIEM/TD partners may utilize ISE as a conduit for taking mitigation actions within the Cisco network infrastructure. SIEM/TD platforms can instruct ISE to undertake quarantine or access-block actions on users and/or device based on ISE policies that have been defined for such actions. &lt;/P&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks! &lt;/P&gt;&lt;P&gt;Octavian&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 04:22:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-and-siem-integration/m-p/2465087#M88242</guid>
      <dc:creator>Octavian Szolga</dc:creator>
      <dc:date>2019-03-11T04:22:04Z</dc:date>
    </item>
    <item>
      <title>ISE and SIEM integration</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-and-siem-integration/m-p/2465088#M88245</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;There is no such docs available till now for ArcSight integration with ISE. I also found only these two links:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/c/dam/en/us/products/collateral/security/identity-services-engine/at_a_glance_c45-728401.pdf"&gt;http://www.cisco.com/c/dam/en/us/products/collateral/security/identity-services-engine/at_a_glance_c45-728401.pdf&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/c/dam/en/us/solutions/enterprise-networks/context-aware-mobility-solution/profile_arcsight_c07-538803.pdf"&gt;http://www.cisco.com/c/dam/en/us/solutions/enterprise-networks/context-aware-mobility-solution/profile_arcsight_c07-538803.pdf&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Feb 2014 03:26:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-and-siem-integration/m-p/2465088#M88245</guid>
      <dc:creator>Naveen Kumar</dc:creator>
      <dc:date>2014-02-13T03:26:34Z</dc:date>
    </item>
    <item>
      <title>ISE and SIEM integration</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-and-siem-integration/m-p/2465089#M88248</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It seems you're right. Cisco will publish the details regarding ISE/SIEM integration late this summer.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Feb 2014 11:28:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-and-siem-integration/m-p/2465089#M88248</guid>
      <dc:creator>Octavian Szolga</dc:creator>
      <dc:date>2014-02-13T11:28:17Z</dc:date>
    </item>
    <item>
      <title>Is there a document available</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-and-siem-integration/m-p/2465090#M88249</link>
      <description>&lt;P&gt;Is there a document available for the integration of ArcSight SIEM with Cisco ISE which includes the milestones and the success criteria? I am not able to find anything specific.&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jun 2015 16:30:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-and-siem-integration/m-p/2465090#M88249</guid>
      <dc:creator>apaldhikar1</dc:creator>
      <dc:date>2015-06-17T16:30:50Z</dc:date>
    </item>
    <item>
      <title>I don' think there will be</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-and-siem-integration/m-p/2465091#M88251</link>
      <description>&lt;P&gt;I don' think there will be any (personal opinion). Some Cisco moderator should answer this one.&lt;/P&gt;&lt;P&gt;If you ask me, all the effort is put into developing pxGrid. If you environment does not work with pxGrid, that's it. It will not work.&lt;/P&gt;</description>
      <pubDate>Wed, 19 Aug 2015 08:57:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-and-siem-integration/m-p/2465091#M88251</guid>
      <dc:creator>Octavian Szolga</dc:creator>
      <dc:date>2015-08-19T08:57:22Z</dc:date>
    </item>
  </channel>
</rss>

