02-09-2018 05:31 AM
Hello Team
We need to see when some mac-address is adding or removing in special identity group in ISE. In which logging categories can we see this? And how it is look like?
Solved! Go to Solution.
02-14-2018 04:53 AM
ISE can do syslog to splunk which has an ISE plug in
Please check their documents
02-12-2018 06:06 AM
Depending on how change made, you may see in Configuration Audit report...
You can also see Identity Group reported in Authentication log. However, the auth log does not flag if change from previous.
/C
02-12-2018 06:35 AM
In report we don't see the name of the group. The point is to monitor the state of special group. We want see adding or removing mac-address to this group.
02-12-2018 06:55 AM
In example, group name is shown. Group is also shown in passed auth log. We do not alarm on endpoints entering/leaving a specified group. I recommend submitting enhancement request to your Cisco account team, or using an external logger with rule that can track members of groups and correlate changes.
02-14-2018 01:09 AM
Can you promt us which product can do that? How can we track this? By syslog or snmp or API?
Can we do this with Splunk?
02-14-2018 04:53 AM
ISE can do syslog to splunk which has an ISE plug in
Please check their documents
11-07-2018 07:28 AM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide