cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
Announcements

This community is for technical, feature, configuration and deployment questions.
For production deployment issues, please contact the TAC! We will not comment or assist with your TAC case in these forums.
Please see How to Ask the Community for Help for other best practices.

155
Views
1
Helpful
2
Replies
Highlighted
Beginner

Can ISE Distributed PSNs Log to Regional SIEM?

Is there a method, or workaround, to limit logging to a regional SIEM for PSNs in that region?

As far as I have read, and understand, logging (and collection filtering) is configured globally, and  there is no way to configure ISE logging to only send logging traffic generated from PSNs within a region (e.g. APAC) to log to a local SIEM configured as a Remote Logging Target also within that region. Has anyone come across a solution or workaround, apart from a separate ISE deployment in the region?

I still require logging to MnT nodes and possibly other remote logging targets for other PSNs in the Cube.

Thank-you

Keith

1 ACCEPTED SOLUTION

Accepted Solutions
Highlighted

It is possible to use DNS to resolve to a local target based on PSN's DNS config or intelligent DNS.  You could use Anycast so that logging target selected is closest destination based on routing metrics.  You can also have a local host entry in PSN to force resolution to a local target.

View solution in original post

2 REPLIES 2
Highlighted
Cisco Employee

Hello,

You cannot configure each PSN to send logs to different logging server today.

But you can raise this  request to ise-pm mailer.

Thanks,

Nidhi

Highlighted

It is possible to use DNS to resolve to a local target based on PSN's DNS config or intelligent DNS.  You could use Anycast so that logging target selected is closest destination based on routing metrics.  You can also have a local host entry in PSN to force resolution to a local target.

View solution in original post

Content for Community-Ad