10-14-2022 11:22 AM
Is there a way to troubleshoot or validate that Cisco ISE is sending syslogs to a "Remote Logging Target"?
I'm trying to set this up with QRadar however its showing that its not receieving any logs from ISE. I've confirmed that IBM has ISE packages to support it but I'm concerned because it says it supports versions 1.1 to 2.2 (seems very dated). Im running 3.1P3 at the moment. I've setup the logging categories to include the new target but still no luck. There is no firewalls between ISE and QRadar.
10-14-2022 11:26 AM
@Lucas Borza run tcpdump on ISE and filter on the syslog IP address to determine whether ISE attempts to communicate.
10-14-2022 11:27 AM
This might sound silly, but I've tried that and its empty. The syslogs are sending in UDP. Would the TCP dump cover that?
10-14-2022 11:35 AM - edited 10-14-2022 11:36 AM
@Lucas Borza have you assigned the remote logging server as a target under the required logging categories?
10-14-2022 12:04 PM
Yes. It turns out the team that manages QRadar had an error in their setup, and they resolved it. I would hope that the TCPDUMP would cover the UDP traffic to at least prove that I am sending the logs.
10-15-2022 07:11 AM
Covered in one of our ISE Webinars. Now available in the CiscoISE YouTube Channel.
▶ ISE Initial Setup and Operations
12:00 Syslogs and Remote Logging Targets
15:09 Logging Categories and Example Syslogs
17:05 Authentication Syslogs from Meraki Dashboard
19:33 Syslog Message Catalog and Export
20:37 Syslog Collection Filters
10-15-2022 08:17 AM
I'm thinking something is up with QRadar not showing the "Notice" syslogs. I have my logging categories setup correctly but I'm looking to see the authentication/authorization logs from every attempt. The goal is to have it so I can trigger an alert if a device is Anomalous or if it hits an Authorization Policy I set for quarantine. I saw in the documentation with QRadar they support versions 1.1 to 2.2 which I find it pretty dated. Maybe they don't accept all syslogs from ISE since I'm running 3.1P3.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide