09-06-2019 06:23 AM
I am curious to understand more about the options of how to retain logs for more than a few days and what ability there is to archive to something like an S3 bucket.
I am trying to retain about 30-60 days of logs especially tacacs logins, and tacacs command accounting.
What are people doing? I am running ISE 2.2 on VM.
09-06-2019 06:51 AM
Unless you have a small appliance and a crazy amount of activity, the ISE database should be able to hold more than a few days of logging data. Unless you have your operational data purging configured to a small number of days. What most customers do is forward Syslog events for authentication to a Syslog server to keep it for audit/compliance reasons. Usually the Security teams want those logs anyway for their SIEM tools. Configure an external Syslog server and then configure which types of logs you want to send to that server.
The other way is to do a daily backup of the operational data to an SFTP, FTP, NFS, or other server/repository. But that data is not as easy to parse as Syslog is. That is more so in case you have to rebuild your ISE environment and want to restore the operational data. Syslog is what you are looking for.
09-06-2019 09:07 AM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide