10-07-2019 03:46 PM
I am looking for Configuration change report in ISE. When I execute report it is full with below two events
'Shutdown secure connection with TLS peer'
'Open secure connection with TLS peer'
So even single day report is of 300Mb with lots of unwanted events. is there any way to edit this report to log only configuration changes.
I am using ISE on 2.4.0.357 Patch 5
Solved! Go to Solution.
10-07-2019 05:33 PM
I just looked at the message catalog and those TLS messages are part of the "Administrative and Operational Audit" category at the INFO level. That is why they are showing up in the report. There really isn't much you can do other than try the "Advanced Filter" on the report and filter out those message types. Then save it in "My Reports".
10-07-2019 04:16 PM
What report are you looking at in ISE?
The configuration changes report is under Operations->Reports->Reports->Audit->Change Configuration Audit. That shows any changes made to the system by administrators or even the system itself such as posture updates or profiler feed updates. Once you have the report open, you can use the quick filters to filter in on what you want. If it is still too much to go through, you can export the report to CSV and use Excel to massage it to your liking.
10-07-2019 04:41 PM
Thanks for the reply, Yes I am looking for the configuration changes in ISE by administrator or system itself. I exported this port for 1 days and I can see around 1048575 entry in that cvs and out of those only 1 was for configuration change and remaining entry are related to connection with TLS peer. please find below table,
Row LabelsCount of 'LOGGED AT'Grand Total1048575
'Changed configuration' | 1 |
'Open secure connection with TLS peer' | 526108 |
'Shutdown secure connection with TLS peer' | 522466 |
so question is why are we getting connection with TLS peer logs in configuration change audit? is there any way to suppress this event. as when I try to export this report for last 7 days it is taking forever. Hence trying to find out if any way to modify report or create custom report to have only configuration changes for the change management compliance audit.
10-07-2019 05:33 PM
I just looked at the message catalog and those TLS messages are part of the "Administrative and Operational Audit" category at the INFO level. That is why they are showing up in the report. There really isn't much you can do other than try the "Advanced Filter" on the report and filter out those message types. Then save it in "My Reports".
10-10-2019 10:37 AM
10-10-2019 12:53 PM
This would have to be submitted as a bug or enhancement request. I do agree with you that the report should only include actual configuration changes and not connection events. Open a TAC case and have them file a bug.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide