it's ICMP based, if it's 2 times down for 5seconds each time (so if it's down for 10seconds), the device is considered to be down. Sometimes ISE is down for longer than 1minute.
It has also nothing to do with our network.
I've configured backups 1x per month (operational and configuration logs, but backup is being done not on the same day).
And data purging check is being done every night at 4am, I checked data purging audit log and downtimes, but as I said, downtimes are different. E.g today it was down at 04:51 am and 05:05 am. Then on 30.08 at 03:53am, 03:11am,02:40am,01:29am,00:01am,
then on 29.08 at 11:59 pm, 03:35am,01:36am,05:06am
then on 28.08. at 05:03 and 04:59 (this time it was just the sponsor-page, which wasn't reachable, the IP of the device was pingable) and on the same day also at 04:29am
then on 26.08 at 04:15am
then on 25.08 at 09:28PM
So that's why I need helpful logfiles. Today I went through ALL logs available with command: show logging system, but I couldn't find anything.
Transferring Crash file from standby: Login to the Active WLC in HA.
From CLI: (Cisco Controller) >transfer upload datatype crash (Cisco
Controller) >transfer upload filename (Cisco
Controller) >transfer upload mode tftp (Cisco Controller) >transfer
This is the start of a display filter cross reference between Wireshark
and OmniPeek. The 1st installment is a table of advanced filters. More
filters will be added as time allows. It is a living doc, so check back
for changes every so often Please feel f...