Writing a Splunk report that looks for multiple users logged into the same machine at or around the same time frame. I can’t think of an ISE value that would indicate a user (such as myself) logging into a machine that you’d potentially be working on. Hoping to get some advice on how to approach this.
Hi, In Cisco ISE message catlog, there is a field for xx:xx:xx:xx/host_name which can be used to correlate this information.