08-24-2023 12:42 PM - edited 08-24-2023 12:43 PM
Hi all;
consider the following figure, captured from "Designing ISE for Scale & High Availability" Cisco Live session in 2018:
As you can see, it mentions that NADs and ASAs can directly send SYSLOG messages to MnT nodes! (as far as I know, MnT nodes can only process SYSLOG messages from PSNs and PANs...)
Can anyone confirm that?
Solved! Go to Solution.
08-24-2023 03:59 PM
Technically the MnT can collect these logs, but it's not best practice to do so.
Sending syslog from the NADs was only ever intended as a temporary solution for troubleshooting. I don't believe the log correlation from the ASA is still a thing.
In general, we would recommend sending syslog from various NADs, Firewalls, and ISE nodes to a SIEM (like Splunk) for correlation and reporting (especially for historical logging)
08-24-2023 03:59 PM
Technically the MnT can collect these logs, but it's not best practice to do so.
Sending syslog from the NADs was only ever intended as a temporary solution for troubleshooting. I don't believe the log correlation from the ASA is still a thing.
In general, we would recommend sending syslog from various NADs, Firewalls, and ISE nodes to a SIEM (like Splunk) for correlation and reporting (especially for historical logging)
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide