cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
543
Views
0
Helpful
5
Replies

Sending logs to MnT nodes

Antonio Macia
Level 3
Level 3

Hello,

 

At some Cisco talk, I've heard that sending WLC, ASA, or switches logs to the MnT is recommended for richer visibility. What are the real benefits of this and what new information can ISE take from these logs? Will not impact on the MnT node performance?

 

Regards.

1 Accepted Solution

Accepted Solutions

howon
Cisco Employee
Cisco Employee

There is small benefit as admin can see the logs from the switches without having to login to each switch. ISE merges the syslog event from the switch with live log. But this is not recommended beyond the pilot stage of the ISE deployment as it impacts ISE load as well as issues with session tracking. Aside from the switch, if ASA sends web access events to MnT, ISE can correlate guest users with web access events from the ASA for guest access log. If using guest access event correlation, make sure to configure ASA to only send web access event as not to overload the MnT node.

View solution in original post

5 Replies 5

Jason Kunst
Cisco Employee
Cisco Employee
Which cisco live?

This is only for troubleshooting purposes. Please see cisco live information for ISE performance and scale at it says it there under the training links for BRKSEC-3432
https://community.cisco.com/t5/security-documents/ise-performance-amp-scale/ta-p/3642148#toc-hId-118574828



For long term rich logs look into Cisco DNA Assurance and/or splunk

Thank you Jason,

 

It was at some partner training. I will skip this for the moment then.

 

regards.

Thank you Jason,

 

It was at some partner training. I will skip this for the moment then.

 

regards.

Can you please share the info with me directly at jakunst@cisco.com

howon
Cisco Employee
Cisco Employee

There is small benefit as admin can see the logs from the switches without having to login to each switch. ISE merges the syslog event from the switch with live log. But this is not recommended beyond the pilot stage of the ISE deployment as it impacts ISE load as well as issues with session tracking. Aside from the switch, if ASA sends web access events to MnT, ISE can correlate guest users with web access events from the ASA for guest access log. If using guest access event correlation, make sure to configure ASA to only send web access event as not to overload the MnT node.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: