09-04-2018 12:50 PM
Hello Team,
Could you confirm: is it possible for ISE to send syslog message for every new WMI session discovered passively ?
As far as i see in my Splunk: it's NOT. Passiveid service is just for service (not for dataplane/sessions).
(i have almost all components configured to send syslogs to Splunk).
Please confirm - maybe i am missing something.
ISE not doing any authentication.
Thanks,
Solved! Go to Solution.
09-04-2018 03:09 PM
is your flow similar to the one described in this nicely written Techzone article? If so, the answer is Yes.
Do you have access to ISE & did you check the Live logs?
- Krish
09-06-2018 08:23 AM
In that case no Syslogs may be available. Needs to be a new feature & please connect with the ISE PM team.
09-04-2018 03:09 PM
is your flow similar to the one described in this nicely written Techzone article? If so, the answer is Yes.
Do you have access to ISE & did you check the Live logs?
- Krish
09-05-2018 03:51 AM
Hi Krish,
Thanks for the help.
My use case is different - as mentioned ISE is not doing any authentication - with Easy Connect it does.
So i do assume the answer is: ISE is not able to send syslog for passively discovered mappings/sessions, but only for those for which authentication is done.
Correct ?
Thanks,
Michal
09-05-2018 09:13 AM
If the flow is different from what is documented in the link I sent you, then the answer depends. Can you verify what you see in ISE logs?
- Krish
09-06-2018 05:35 AM - edited 09-06-2018 05:58 AM
I see no logs in ISE - as i have mentioned already: ISE is not doing ANY authentication ;)
Thanks,
09-06-2018 08:23 AM
In that case no Syslogs may be available. Needs to be a new feature & please connect with the ISE PM team.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide