<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Integerating MSE/WLC into SIEM? in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/integerating-mse-wlc-into-siem/m-p/2225552#M7194</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you set a syslog level, only those messages whose severity is equal to or less than that level are sent to the syslog servers. For example, if you set the syslog level to Warnings (severity level 4), only those messages whose severity is between 0 and 4 are sent to the syslog servers.&lt;BR /&gt;&lt;BR /&gt;Sent from Cisco Technical Support iPhone App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sun, 05 May 2013 13:37:57 GMT</pubDate>
    <dc:creator>Scott Fella</dc:creator>
    <dc:date>2013-05-05T13:37:57Z</dc:date>
    <item>
      <title>Integerating MSE/WLC into SIEM?</title>
      <link>https://community.cisco.com/t5/wireless/integerating-mse-wlc-into-siem/m-p/2225549#M7191</link>
      <description>&lt;P&gt;I'm from the sec team, and the company in which i work in is using Wireless Control System Plus with MSE (mobility security engine).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now using syslog I'm interested in detecting rogue access points, What source should i enable syslog either controller or mse? I want to brng that logs to SIEM for higher correlation. I'm still confused.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are using cisco aironet 3500 series .&lt;/P&gt;&lt;P&gt;Lan controller 5500&lt;/P&gt;&lt;P&gt;MSE 3300 series &lt;/P&gt;&lt;P&gt;WCS v 5.0&lt;/P&gt;</description>
      <pubDate>Sun, 04 Jul 2021 07:01:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/integerating-mse-wlc-into-siem/m-p/2225549#M7191</guid>
      <dc:creator>asad ali</dc:creator>
      <dc:date>2021-07-04T07:01:41Z</dc:date>
    </item>
    <item>
      <title>Re: Integerating MSE/WLC into SIEM?</title>
      <link>https://community.cisco.com/t5/wireless/integerating-mse-wlc-into-siem/m-p/2225550#M7192</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Well first off, the MSE is a Mobility Services Engine not a security engine. You also have to make sure you have the correct code versions on your WLC, WCS and MSE. The WCS version is very old and the rule of thumb is to have the WCS and MSE an equal or higher version than the WLC. The WLC only supports the WLC on v7.0.x. You might have to upgrade your WCS to Prime infrastructure. Please refer to the compatibility matrix below.&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://www.cisco.com/en/US/docs/wireless/controller/5500/tech_notes/Wireless_Software_Compatibility_Matrix.html" target="_blank"&gt;http://www.cisco.com/en/US/docs/wireless/controller/5500/tech_notes/Wireless_Software_Compatibility_Matrix.html&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Rogue detection can come from the WLC, but it might be unusable if you have many rogue AP's being detected especially if your in a downtown building for example.&lt;BR /&gt;&lt;BR /&gt;Sent from Cisco Technical Support iPhone App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 05 May 2013 13:26:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/integerating-mse-wlc-into-siem/m-p/2225550#M7192</guid>
      <dc:creator>Scott Fella</dc:creator>
      <dc:date>2013-05-05T13:26:01Z</dc:date>
    </item>
    <item>
      <title>Re: Integerating MSE/WLC into SIEM?</title>
      <link>https://community.cisco.com/t5/wireless/integerating-mse-wlc-into-siem/m-p/2225551#M7193</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you for your respons.&lt;/P&gt;&lt;P&gt;I was seeing the syslog options In the facility drop down menu , there was list of options (kernel,mail,cron) by defualt its set to local use 0. Does this level mean that it caters for all the levels that are less or equal then its.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;E.g&lt;/P&gt;&lt;P style="margin-top: px; margin-bottom: px; line-height: normal;"&gt;&lt;STRONG&gt;Kernel&lt;/STRONG&gt; = Facility level 0 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin-top: px; margin-bottom: px; line-height: normal;"&gt;•&lt;STRONG&gt;User Process&lt;/STRONG&gt; = Facility level 1 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin-top: px; margin-bottom: px; line-height: normal;"&gt;•&lt;STRONG&gt;Mail&lt;/STRONG&gt; = Facility level 2 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin-top: px; margin-bottom: px; line-height: normal;"&gt;•&lt;STRONG&gt;System Daemons&lt;/STRONG&gt; = Facility level 3 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin-top: px; margin-bottom: px; line-height: normal;"&gt;•&lt;STRONG&gt;Authorization&lt;/STRONG&gt; = Facility level 4 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin-top: px; margin-bottom: px; line-height: normal;"&gt;•&lt;STRONG&gt;Syslog&lt;/STRONG&gt; = Facility level 5 (default value) &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin-top: px; margin-bottom: px; line-height: normal;"&gt;•&lt;STRONG&gt;Line Printer&lt;/STRONG&gt; = Facility level 6 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin-top: px; margin-bottom: px; line-height: normal;"&gt;•&lt;STRONG&gt;USENET&lt;/STRONG&gt; = Facility level 7 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin-top: px; margin-bottom: px; line-height: normal;"&gt;•&lt;STRONG&gt;Unix-to-Unix Cop&lt;/STRONG&gt;y = Facility level 8 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin-top: px; margin-bottom: px; line-height: normal;"&gt;•&lt;STRONG&gt;Cron&lt;/STRONG&gt; = Facility level 9 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin-top: px; margin-bottom: px; line-height: normal;"&gt;•&lt;STRONG&gt;FTP Daemon&lt;/STRONG&gt; = Facility level 11 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin-top: px; margin-bottom: px; line-height: normal;"&gt;•&lt;STRONG&gt;System Use 1&lt;/STRONG&gt; = Facility level 12 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin-top: px; margin-bottom: px; line-height: normal;"&gt;•&lt;STRONG&gt;System Use 2&lt;/STRONG&gt; = Facility level 13 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin-top: px; margin-bottom: px; line-height: normal;"&gt;•&lt;STRONG&gt;System Use 3&lt;/STRONG&gt; = Facility level 14 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin-top: px; margin-bottom: px; line-height: normal;"&gt;•&lt;STRONG&gt;System Use 4&lt;/STRONG&gt; = Facility level 15 &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 05 May 2013 13:33:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/integerating-mse-wlc-into-siem/m-p/2225551#M7193</guid>
      <dc:creator>asad ali</dc:creator>
      <dc:date>2013-05-05T13:33:29Z</dc:date>
    </item>
    <item>
      <title>Re: Integerating MSE/WLC into SIEM?</title>
      <link>https://community.cisco.com/t5/wireless/integerating-mse-wlc-into-siem/m-p/2225552#M7194</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you set a syslog level, only those messages whose severity is equal to or less than that level are sent to the syslog servers. For example, if you set the syslog level to Warnings (severity level 4), only those messages whose severity is between 0 and 4 are sent to the syslog servers.&lt;BR /&gt;&lt;BR /&gt;Sent from Cisco Technical Support iPhone App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 05 May 2013 13:37:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/integerating-mse-wlc-into-siem/m-p/2225552#M7194</guid>
      <dc:creator>Scott Fella</dc:creator>
      <dc:date>2013-05-05T13:37:57Z</dc:date>
    </item>
    <item>
      <title>Re: Integerating MSE/WLC into SIEM?</title>
      <link>https://community.cisco.com/t5/wireless/integerating-mse-wlc-into-siem/m-p/2225553#M7195</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That i understand, but what i don't understand is the faciliy levels? how are they define and set.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 05 May 2013 13:44:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/integerating-mse-wlc-into-siem/m-p/2225553#M7195</guid>
      <dc:creator>asad ali</dc:creator>
      <dc:date>2013-05-05T13:44:45Z</dc:date>
    </item>
  </channel>
</rss>

