Loading

Cisco ISE

Version 1.26.1 (View all)
Compatible Kibana version(s) 8.11.0 or higher
9.0.0 or higher
Supported Serverless project types
What's this?
Security
Observability
Subscription level
What's this?
Basic
Level of support
What's this?
Elastic

The Cisco ISE integration collects and parses data from Cisco Identity Services Engine (ISE) using TCP/UDP.

This module has been tested against Cisco ISE server version 3.1.0.518.

  • Enable the integration with the TCP/UDP input.
  • Sign in to Cisco ISE Portal.
  • Configure Remote Syslog Collection Locations.
    • Procedure
      1. In Cisco ISE Administrator Portal, go to Administration > System > Logging > Remote Logging Targets.
      2. Click Add. Cisco ISE server setup image
      3. Enter all the Required Details.
      4. Set the maximum length to 8192.
      5. Click Submit.
      6. Go to the Remote Logging Targets page and verify the creation of the new target.
  • It is recommended to have 8192 as Maximum Message Length. Segmentation for certain logs coming from Cisco ISE might cause issues with field mappings.

Reference link for Cisco ISE Syslog: Here

This is the log dataset.