cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
371
Views
0
Helpful
1
Replies

Difference between IS Operational Backups and Operational Data Purging

Danny Dulin
Level 2
Level 2

We are conducting regular Operational backups of our ISE nodes.

We are also exporting RADIUS and TACACS operational data to a repository before purging.

Documentation states that "Operational Data Backup: Contains Monitoring and Troubleshooting data."

Is RADIUS and TACACS operational data included in "Monitoring and Troubleshooting data?" 

If so, does that mean we are saving redundant data?

On top of the fact we are sending the RADIUS and TACACS data to a SIEM.

1 Accepted Solution

Accepted Solutions

balaji.bandi
Hall of Fame
Hall of Fame

When you run an Operational Backup (backup <name> repository <repo> operational), ISE takes a snapshot of the current ADE-OS Monitoring and Troubleshooting (MnT) database. This includes:
RADIUS & TACACS+ Live Logs, Active sessions, and the indexed data used to generate built-in ISE reports.

If so, does that mean we are saving redundant data?

Yes, as I know.

On top of the fact we are sending the RADIUS and TACACS data to a SIEM.

This is most of the logs used to correlate SIEM configuration.

The Operational Backup is purely to fix ISE if the MnT node's database becomes corrupted.

Purge Data -  Purge Settings (under Administration > Management > Logging > Data Purging) to see exactly how many days of data are being bundled into those exports versus what is kept in the live database.

BB

=====️ Preenayamo Vasudevam ️=====

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

View solution in original post

1 Reply 1

balaji.bandi
Hall of Fame
Hall of Fame

When you run an Operational Backup (backup <name> repository <repo> operational), ISE takes a snapshot of the current ADE-OS Monitoring and Troubleshooting (MnT) database. This includes:
RADIUS & TACACS+ Live Logs, Active sessions, and the indexed data used to generate built-in ISE reports.

If so, does that mean we are saving redundant data?

Yes, as I know.

On top of the fact we are sending the RADIUS and TACACS data to a SIEM.

This is most of the logs used to correlate SIEM configuration.

The Operational Backup is purely to fix ISE if the MnT node's database becomes corrupted.

Purge Data -  Purge Settings (under Administration > Management > Logging > Data Purging) to see exactly how many days of data are being bundled into those exports versus what is kept in the live database.

BB

=====️ Preenayamo Vasudevam ️=====

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help