06-08-2023 04:03 PM
Hello everyone!
We are using syslogs for monitoring. I have multiple deployments that are very similar to each other.
But I just found out that one of them is different when comes to syslog messages.
My syslog monitoring is expecting to see this message:
Jun 2 00:00:00 hostname CISE_Administrative_and_Operational_Audit 0007666335 1 0 2023-06-02 00:00:00.323 +00:00 0741901856 60166 NOTICE Certificate: Certificate will expire soon, ConfigVersionId=442, OperationMessageText=Local certificate 'something' will expire in 60 days,
But I get this instead:
Jun 8 00:00:10 hostname CISE_Alarm WARN: Local certificate 'C=US;ST=Somewhere;L=Arlington;O=The Something Corporation;CN=something.something.com#Entrust Certification Authority - L1K#000
05' will expire in 10 days : Server=something
I was expecting (per the cisco ise syslog list) that every syslog has its own code, why CISE_Alarm bypass that convention?
Where to adjust this configuration please?
I want all my syslogs to follow the catalog aka CISE_Administrative_and_Operational_Audit instead of CISE_Alarm.
Solved! Go to Solution.
06-08-2023 05:44 PM
Alarm messages don't show the message code. There is an enhancement already filed for this change:
https://bst.cisco.com/bugsearch/bug/CSCvw55478
06-08-2023 05:44 PM
Alarm messages don't show the message code. There is an enhancement already filed for this change:
https://bst.cisco.com/bugsearch/bug/CSCvw55478
06-10-2023 02:42 AM
Impacted ISE version 2.7.0.356 (patches 3,6,7,8)
@poongarg - do you think that another patch or upgrade would resolve the issue? Is there anything we can do to get the unique message codes back?
I am supporting 10 other deployments running on different versions, this is the only environment I am facing the bug.
Would be worth to open TAC for this?
06-10-2023 05:28 PM
The enhancement is filed on top of ISE 3.1 and yet not incorporated in any release. So upgrading the patch or version will not help.
06-10-2023 03:12 AM
I could rephrase as missing "OperationMessageText=" as part of the syslog. (I can live without the unique codes, OperationMessageText is more important for me)
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide