Cisco ISE and external syslog server

Answered Question
Jul 17th, 2012
User Badges:

Hi Security Experts,


We are starting with deploying cisco ISE (Identity Services Engine) in our network. We have allocated 250GB space for (Admin+Monitor) ISE node.

I want to know if we can send the logs from monitoring node to external syslog server after a defined time interval.


For example, logs which are more than 10 days old should be sent to external syslog server. So basically our monitoring node will have logs which are at the max 9 days old. Is it possible? Could you point me to some doc which explains configuration of the same?


Thanks,

Kashish

Correct Answer by Tarik Admani about 5 years 1 month ago

No this isnt possible via syslog. What you are looking for is database purging, so that the monitoring database is purged after a specific time interval. Here is a guide that will help shed some light on this:


http://www.cisco.com/en/US/docs/security/ise/1.1/user_guide/ise_mnt.html#wp1054328


Tarik Admani
*Please rate helpful posts*

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 5 (1 ratings)
Loading.
Correct Answer
Tarik Admani Tue, 07/17/2012 - 21:21
User Badges:
  • Green, 3000 points or more

No this isnt possible via syslog. What you are looking for is database purging, so that the monitoring database is purged after a specific time interval. Here is a guide that will help shed some light on this:


http://www.cisco.com/en/US/docs/security/ise/1.1/user_guide/ise_mnt.html#wp1054328


Tarik Admani
*Please rate helpful posts*

Actions

This Discussion

Related Content