integration-docs
Loading

Cisco ISE

Stack 9.0.0 Serverless Observability Serverless Security

Version 1.29.0 (View all)
Subscription level
What's this?
Basic
Level of support
What's this?
Elastic
Ingestion method(s) File, Network Protocol

The Cisco ISE integration collects and parses data from Cisco Identity Services Engine (ISE) using TCP/UDP.

This module has been tested against Cisco ISE server version 3.1.0.518.

  • Enable the integration with the TCP/UDP input.
  • Sign in to Cisco ISE Portal.
  • Configure Remote Syslog Collection Locations.
    • Procedure
      1. In Cisco ISE Administrator Portal, go to Administration > System > Logging > Remote Logging Targets.
      2. Click Add. Cisco ISE server setup image
      3. Enter all the Required Details.
      4. Set the maximum length to 8192.
      5. Click Submit.
      6. Go to the Remote Logging Targets page and verify the creation of the new target.
  • It is recommended to have 8192 as Maximum Message Length. Segmentation for certain logs coming from Cisco ISE might cause issues with field mappings.

Reference link for Cisco ISE Syslog: Here

This is the log dataset.

This integration includes one or more Kibana dashboards that visualizes the data collected by the integration. The screenshots below illustrate how the ingested data is displayed.