cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
357
Views
0
Helpful
6
Replies

Cisco ISE Showing All Live Sessions Need to filter

Csnoc314
Level 1
Level 1

we're currently using Cisco ISE for user identity management, and we've noticed that ISE is showing all live sessions, including background/system logins and service accounts. However, for our operational needs, we only want to see interactive user logins and RDP session details.

we have install PICAgent in AD server and this live sessions are getting from AD

Is there a way to filter or configure Cisco ISE to only display live sessions for interactive users (those actively logged in via console or RDP) and exclude system or background accounts?

We are primarily interested in getting clean session data to integrate with Cisco FMC for correlation and visibility.

6 Replies 6

You can configure Passive ID filters. But why do you need ISE-PIC at all? What is the use-case? Why not upgrade the FMC 7.6 or 7.7 and use the native user-agent?

we are only allowed by the management to upgrade the suggested version from the Manufacturer as per Cisco R&D suggested version is only 7.4 so only optio is to go with ISE-PIC if you can give tutorial or way to configure Passive ID filter.

Hi @Csnoc314 ,

 please take a look at: Filter Passive Identity Services.

 

Hope this helps !!!

Hi @marc ,

Thanks but it after enabling this option still real interactive user not showing in live session. our main purpose for this to track the user .

Hi @Csnoc314 ,

 got it !!!

 At Operations > RADIUS > Live Sessions > the Session Source column are able to show:

  • RADIUS
  • Passive ID
  • Passive ID - RADIUS

Does this information help you ?

 


Hi
I use Collection Filters (Administration > System > Logging > Collection Filters) to filter out certain usernames from the live logs

You can also use the attributes show below to filter on.

hth
Andy

ise collection filter.png