cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1449
Views
0
Helpful
6
Replies

ISE Identity groups logging

alyautdinov
Level 1
Level 1

Hello Team

We need to see when some mac-address is adding or removing in special identity group in ISE. In which logging categories can we see this? And how it is look like?

1 Accepted Solution

Accepted Solutions

ISE can do syslog to splunk which has an ISE plug in

Please check their documents

View solution in original post

6 Replies 6

Craig Hyps
Level 10
Level 10

Depending on how change made, you may see in Configuration Audit report...

You can also see Identity Group reported in Authentication log.  However, the auth log does not flag if change from previous.

/C

In report we don't see the name of the group. The point is to monitor the state of special group. We want see adding or removing mac-address to this group.

In example, group name is shown.  Group is also shown in passed auth log.  We do not alarm on endpoints entering/leaving a specified group.  I recommend submitting enhancement request to your Cisco account team, or using an external logger with rule that can track members of groups and correlate changes.

Can you promt us which product can do that? How can we track this? By syslog or snmp or API?

Can we do this with Splunk?

ISE can do syslog to splunk which has an ISE plug in

Please check their documents

Hi Jason ,

Do you know which Logging Category & at which Severity , produce this specific information of log ? I mean the name of the identity group .

Thanks

Makis