All Apps and Add-ons

Cisco ISE App/Add-On

plao
Explorer

Looking at the Cisco ISE App/Add_On

The logging level is by default set to debug

I cannot find a file which shows me debug logs for this TA?

/var/log/splunk does not have any specific file for ISE and in /splunk/etc/apps/Splunk_TA as well, there is no file for logs?


Thanks!

 

plao_0-1740067191878.png

 

Labels (1)
0 Karma
1 Solution

livehybrid
SplunkTrust
SplunkTrust

Hi @plao 

The config you've shown shows that it uses a UDP input, therefore I would not expect to see any ISE specific log sources in your logs.

Is there any issue that you are experiencing that you need additional debug logs for?

Please let me know how you get on and consider accepting this answer or adding karma this answer if it has helped.
Regards

Will

View solution in original post

livehybrid
SplunkTrust
SplunkTrust

Hi @plao 

The config you've shown shows that it uses a UDP input, therefore I would not expect to see any ISE specific log sources in your logs.

Is there any issue that you are experiencing that you need additional debug logs for?

Please let me know how you get on and consider accepting this answer or adding karma this answer if it has helped.
Regards

Will

plao
Explorer

Hi

We are working on a Cisco Sec+Splunk course, using the new Cisco Security Cloud App as well as coverage for the old apps like the Cisco ISE App/Add-on. In this course, we have a troubleshooting section, so for ISE, just checking if there are any ISE logs in Splunk for troubleshooting the App/Add-On

 

Thanks!

0 Karma

plao
Explorer

Thanks .. I only see from SNA app 

plao_0-1740071199834.png

 

 

0 Karma

plao
Explorer

plao_0-1740071270229.png

 

0 Karma

plao
Explorer

plao_0-1740070779732.png

 

0 Karma

plao
Explorer
0 Karma

Cievo
Path Finder

Have look at this DOCUMENTATION PAGE. Debugging logs should be send into _internal index. Look at that index.

 

0 Karma

Cievo
Path Finder

Are you talking about this APP?

If so, I don't think is application has it's own debugging log file.

 

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Calling All Security Pros: Ready to Race Through Boston?

Hey Splunkers, .conf25 is heading to Boston and we’re kicking things off with something bold, competitive, and ...

Beyond Detection: How Splunk and Cisco Integrated Security Platforms Transform ...

Financial services organizations face an impossible equation: maintain 99.9% uptime for mission-critical ...

Customer success is front and center at .conf25

Hi Splunkers, If you are not able to be at .conf25 in person, you can still learn about all the latest news ...