All Apps and Add-ons

Cisco ISE host versus NetworkDeviceName

jaracan
Communicator

Hi Team,

Just wanted to check with you what is the difference between host and NetworkDeviceName in Cisco ISE context?

I had use the SPL queries below and have different results.
index=cisco_ise | stats count by host

index=cisco_ise | stats count by NetworkDeviceName

A little background on Architecture, we have Syslog servers (Splunk Forwarders as well) where cisco ise traffic logs are written, then we use Splunk file monitoring to check those cisco ise traffic logs and ingest it to Splunk. We also have Splunk Add-on for Cisco ISE installed on those Syslog servers/Splunk Forwarders. Then we have that Splunk Add-on for Cisco ISE also on our Indexer Tier and Search Tier for field extraction and other conf. On our Search Head, we have the SplunkApp for Cisco ISE.

Regards,
Jaracan

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Vibe-coding, AI, and Splunkcraft: Highlights from the .conf26 Builder Bar

If you stopped by the Builder Bar at .conf26, thank you! This year, we brought ...

Thanks for the Memories: .conf26 Took Learning to New Heights

Thank you, Splunk Community, for making .conf26 in Denver one for the books. From packed Splunk University ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...