07-28-2018 06:37 AM
Is there anyway to keep the hits count on all active policy? After a reboot the accumulated counts are gone.
Solved! Go to Solution.
07-28-2018 08:32 AM
No. The HitCounts are cached in memory only and clear after a ISE service restart.
Please note that such counters are to give a relative measure how the policy rules are matched but not absolute.
ISE has an authentication summary report since ISE 2.3 but it's currently lacking statistics grouped by policy sets -- CSCvf95838. Instead, we may run and export a RADIUS authentications report and use other tools to gather matches on policy set, etc. A fairly popular option is to create a remote syslog target to forward authentication events to a tool like Splunk with Splunk Add-on for Cisco ISE
07-28-2018 08:32 AM
No. The HitCounts are cached in memory only and clear after a ISE service restart.
Please note that such counters are to give a relative measure how the policy rules are matched but not absolute.
ISE has an authentication summary report since ISE 2.3 but it's currently lacking statistics grouped by policy sets -- CSCvf95838. Instead, we may run and export a RADIUS authentications report and use other tools to gather matches on policy set, etc. A fairly popular option is to create a remote syslog target to forward authentication events to a tool like Splunk with Splunk Add-on for Cisco ISE
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide