<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Missing field from Splunk for Cisco Identity Services (ISE) logs: AllowedProtocolMatchedRule. in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Missing-field-from-Splunk-for-Cisco-Identity-Services-ISE-logs/m-p/576653#M75643</link>
    <description>&lt;P&gt;afaik 3.0p2 (i'm not the admin of ISE)&lt;/P&gt;</description>
    <pubDate>Mon, 29 Nov 2021 19:59:46 GMT</pubDate>
    <dc:creator>d1nd141</dc:creator>
    <dc:date>2021-11-29T19:59:46Z</dc:date>
    <item>
      <title>Missing field from Splunk for Cisco Identity Services (ISE) logs: AllowedProtocolMatchedRule.</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Missing-field-from-Splunk-for-Cisco-Identity-Services-ISE-logs/m-p/460632#M56668</link>
      <description>&lt;P&gt;I have a feeling this question will answer a lot of other questions I have.&lt;/P&gt;

&lt;P&gt;This field -  &lt;CODE&gt;AllowedProtocolMatchedRule&lt;/CODE&gt; - is missing from my Cisco ISE logs.  The field is needed to populate data in the Cisco ISE App dashboard.  But I have no record of this field, even going back to the beginning of time.  I'm not sure how to resolve this problem.&lt;/P&gt;</description>
      <pubDate>Wed, 20 May 2020 19:38:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Missing-field-from-Splunk-for-Cisco-Identity-Services-ISE-logs/m-p/460632#M56668</guid>
      <dc:creator>TitanAE</dc:creator>
      <dc:date>2020-05-20T19:38:17Z</dc:date>
    </item>
    <item>
      <title>Re: Missing field from Splunk for Cisco Identity Services (ISE) logs: AllowedProtocolMatchedRule.</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Missing-field-from-Splunk-for-Cisco-Identity-Services-ISE-logs/m-p/460633#M56669</link>
      <description>&lt;P&gt;I'm also having the same problem.  Wish I had an answer for you &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;  What version of ISE are you running.&lt;/P&gt;</description>
      <pubDate>Wed, 20 May 2020 20:23:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Missing-field-from-Splunk-for-Cisco-Identity-Services-ISE-logs/m-p/460633#M56669</guid>
      <dc:creator>TitanAE</dc:creator>
      <dc:date>2020-05-20T20:23:27Z</dc:date>
    </item>
    <item>
      <title>Re: Missing field from Splunk for Cisco Identity Services (ISE) logs: AllowedProtocolMatchedRule.</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Missing-field-from-Splunk-for-Cisco-Identity-Services-ISE-logs/m-p/575983#M75608</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;have the same issue.&lt;BR /&gt;You found a way to solve?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 23 Nov 2021 08:26:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Missing-field-from-Splunk-for-Cisco-Identity-Services-ISE-logs/m-p/575983#M75608</guid>
      <dc:creator>d1nd141</dc:creator>
      <dc:date>2021-11-23T08:26:33Z</dc:date>
    </item>
    <item>
      <title>Re: Missing field from Splunk for Cisco Identity Services (ISE) logs: AllowedProtocolMatchedRule.</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Missing-field-from-Splunk-for-Cisco-Identity-Services-ISE-logs/m-p/576653#M75643</link>
      <description>&lt;P&gt;afaik 3.0p2 (i'm not the admin of ISE)&lt;/P&gt;</description>
      <pubDate>Mon, 29 Nov 2021 19:59:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Missing-field-from-Splunk-for-Cisco-Identity-Services-ISE-logs/m-p/576653#M75643</guid>
      <dc:creator>d1nd141</dc:creator>
      <dc:date>2021-11-29T19:59:46Z</dc:date>
    </item>
  </channel>
</rss>

