All Apps and Add-ons

Cisco ISE App/Add-On

plao
Explorer

Looking at the Cisco ISE App/Add_On

The logging level is by default set to debug

I cannot find a file which shows me debug logs for this TA?

/var/log/splunk does not have any specific file for ISE and in /splunk/etc/apps/Splunk_TA as well, there is no file for logs?


Thanks!

 

plao_0-1740067191878.png

 

Labels (1)
0 Karma
1 Solution

livehybrid
SplunkTrust
SplunkTrust

Hi @plao 

The config you've shown shows that it uses a UDP input, therefore I would not expect to see any ISE specific log sources in your logs.

Is there any issue that you are experiencing that you need additional debug logs for?

Please let me know how you get on and consider accepting this answer or adding karma this answer if it has helped.
Regards

Will

View solution in original post

livehybrid
SplunkTrust
SplunkTrust

Hi @plao 

The config you've shown shows that it uses a UDP input, therefore I would not expect to see any ISE specific log sources in your logs.

Is there any issue that you are experiencing that you need additional debug logs for?

Please let me know how you get on and consider accepting this answer or adding karma this answer if it has helped.
Regards

Will

plao
Explorer

Hi

We are working on a Cisco Sec+Splunk course, using the new Cisco Security Cloud App as well as coverage for the old apps like the Cisco ISE App/Add-on. In this course, we have a troubleshooting section, so for ISE, just checking if there are any ISE logs in Splunk for troubleshooting the App/Add-On

 

Thanks!

0 Karma

plao
Explorer

Thanks .. I only see from SNA app 

plao_0-1740071199834.png

 

 

0 Karma

plao
Explorer

plao_0-1740071270229.png

 

0 Karma

plao
Explorer

plao_0-1740070779732.png

 

0 Karma

plao
Explorer
0 Karma

Cievo
Path Finder

Have look at this DOCUMENTATION PAGE. Debugging logs should be send into _internal index. Look at that index.

 

0 Karma

Cievo
Path Finder

Are you talking about this APP?

If so, I don't think is application has it's own debugging log file.

 

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Unlock What’s Next: The Splunk Cloud Platform at .conf25

In just a few days, Boston will be buzzing as the Splunk team and thousands of community members come together ...