cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
487
Views
0
Helpful
5
Replies

Report for new devices only?

Josh Morris
Level 3
Level 3

I'm moving toward low-impact mode and am trying to answer the question of "How many new users can we expect to see after we convert to low-impact?" so I'll know how to staff resources on day n to properly resolve issues. We have Splunk and can generate some so-so reports, but its still not great. Any ideas?

5 Replies 5

What do you mean by "new users"?  

In this case, it would mean new devices that come online. Ex: We have 50,000 endpoints and have properly classified all 50,000 and tomorrow we have 50,001 devices. I would like to be able to have a regular report of the new endpoints from that time periot.

Why exactly?  If they match your policy, etc what value does this offer?  You can certainly do something like this in Splunk but I'm not sure how to accomplish it.

Low-impact ""monitor"" ?

If yes then all endpoint connect to SW will known by ISE.

Do you want to use context visible to add known endpoint to identity group?

MHM

Ultimately, yes. We would want to properly classify any new endpoints into an already existing profile/rule. At this point, I'm trying to determine what the day 2 impact would be of moving our default rule action though.