All Apps and Add-ons

One user logging into multiple systems at or around the same time - Cisco ISE

New Member

Writing a Splunk report that looks for multiple users logged into the same machine at or around the same time frame. I can’t think of an ISE value that would indicate a user (such as myself) logging into a machine that you’d potentially be working on. Hoping to get some advice on how to approach this.

0 Karma

Contributor

Hi, In Cisco ISE message catlog, there is a field for xx:xx:xx:xx/host_name which can be used to correlate this information.

0 Karma