OK, just to go over the information flow to ensure all is working (needless to say it isn't--I'm missing something)
ISE via syslog to one machine (ubuntu server) running syslog, indexer, and search head. Understood the universal forwarder on our normal syslog server (Windows) wont work because there's no python to run the scripts.
Syslog IS populating with messages: made a local/inputs.conf in the addon folder to monitor the var/log/ (server) --unknown if this is working-- and a search for "sourcetype=cisco:ise:syslog" is empty.
Any help is appreciated.
OK.. It helps to spell the folder correctly in the inputs.conf. populating splunk.. now to check the app.
OK.. It helps to spell the folder correctly in the inputs.conf. populating splunk.. now to check the app.
In the app, all panels are searched on "eventtype-cisco-ise" Placed a wildcard "*" at the end of "ISE" and they came alive.