01-26-2018 12:09 PM
Are all commands logged in ISE or just successful commands that are accepted by the device? If all commands are being logged by ISE how do I view the failed attempts? For example, if a user has access to view an interface but does not have access to make configuration will ISE log an attempt if the user tries to make a config change to the interface?
Solved! Go to Solution.
01-26-2018 01:49 PM
This are a few things here:
So with all that being said. Whatever commands you are authorizing will show up in the TACACS live logs and TACACS authorization report. Both are very tricky to view because you don't see the command attempted until you drill into the details of the record, but accepts and denies are logged.
If you want a detail of the commands executed you can run a TACACS accounting report. That will give you the full picture about what happened when the user was on the switch. Denied commands are not accounted for, but they would show up in the authorization report/live logs.
01-26-2018 01:49 PM
This are a few things here:
So with all that being said. Whatever commands you are authorizing will show up in the TACACS live logs and TACACS authorization report. Both are very tricky to view because you don't see the command attempted until you drill into the details of the record, but accepts and denies are logged.
If you want a detail of the commands executed you can run a TACACS accounting report. That will give you the full picture about what happened when the user was on the switch. Denied commands are not accounted for, but they would show up in the authorization report/live logs.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide