All Apps and Add-ons

Cisco ISE App/Add-On

plao
Explorer

Looking at the Cisco ISE App/Add_On

The logging level is by default set to debug

I cannot find a file which shows me debug logs for this TA?

/var/log/splunk does not have any specific file for ISE and in /splunk/etc/apps/Splunk_TA as well, there is no file for logs?


Thanks!

 

plao_0-1740067191878.png

 

Labels (1)
0 Karma
1 Solution

livehybrid
SplunkTrust
SplunkTrust

Hi @plao 

The config you've shown shows that it uses a UDP input, therefore I would not expect to see any ISE specific log sources in your logs.

Is there any issue that you are experiencing that you need additional debug logs for?

Please let me know how you get on and consider accepting this answer or adding karma this answer if it has helped.
Regards

Will

View solution in original post

livehybrid
SplunkTrust
SplunkTrust

Hi @plao 

The config you've shown shows that it uses a UDP input, therefore I would not expect to see any ISE specific log sources in your logs.

Is there any issue that you are experiencing that you need additional debug logs for?

Please let me know how you get on and consider accepting this answer or adding karma this answer if it has helped.
Regards

Will

plao
Explorer

Hi

We are working on a Cisco Sec+Splunk course, using the new Cisco Security Cloud App as well as coverage for the old apps like the Cisco ISE App/Add-on. In this course, we have a troubleshooting section, so for ISE, just checking if there are any ISE logs in Splunk for troubleshooting the App/Add-On

 

Thanks!

0 Karma

plao
Explorer

Thanks .. I only see from SNA app 

plao_0-1740071199834.png

 

 

0 Karma

plao
Explorer

plao_0-1740071270229.png

 

0 Karma

plao
Explorer

plao_0-1740070779732.png

 

0 Karma

plao
Explorer
0 Karma

Cievo
Path Finder

Have look at this DOCUMENTATION PAGE. Debugging logs should be send into _internal index. Look at that index.

 

0 Karma

Cievo
Path Finder

Are you talking about this APP?

If so, I don't think is application has it's own debugging log file.

 

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...