08-24-2022 02:52 AM
What I would like to have confirmation from Cisco is that we are saving same data to the MNTs and to our Syslog Servers, so we can safely purge that data without compromising our audit commitments.
Wherever we have both MNTs and SysLog Servers configured, is there any difference between the logs MNTs and the logs that are sent to Syslog? Are exactly the same ones? (e.g. the Accounting logs send to LogCollector and to SLG1 contain exactly the same info with no variation?)
Any Cisco ISE Guru that can help with this.
Solved! Go to Solution.
08-25-2022 06:26 PM
You could take a sample endpoint and check on your SYSLOG server whether or not you can find that same Accounting record (for example). It always depends on what Logging Categories you have enabled when sending those to external SYSLOG receivers. e.g. the Category called "RADIUS Accounting" is one that should have the external SYSLOG as Target. If you can't get access to the external SYSLOG server then simply run a tcpdump on the MnT server(s) to capture the outgoing SYSLOG requests - wireshark does a pretty good job at decoding them. I think internally, ISE uses SYSLOG between PSN and MnT to build up the Live Logs. So in principle the SYSLOGs the get forwarded to external receivers should contain the same data.
08-25-2022 06:26 PM
You could take a sample endpoint and check on your SYSLOG server whether or not you can find that same Accounting record (for example). It always depends on what Logging Categories you have enabled when sending those to external SYSLOG receivers. e.g. the Category called "RADIUS Accounting" is one that should have the external SYSLOG as Target. If you can't get access to the external SYSLOG server then simply run a tcpdump on the MnT server(s) to capture the outgoing SYSLOG requests - wireshark does a pretty good job at decoding them. I think internally, ISE uses SYSLOG between PSN and MnT to build up the Live Logs. So in principle the SYSLOGs the get forwarded to external receivers should contain the same data.
08-26-2022 11:03 PM
Hi @Grizzelz ,
please take a look at Administration > System > Logging > Logging Categories, check the Targets column and check what you are sending to the LogCollector (MnT) and to your Syslog.
Hope this helps !!!
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide