Cisco ISE Custom Alert that can hit directly Cisco ISE API to block mac-address
Cisco ISE Custom Alert that can hit directly Cisco ISE API to block mac-address
The Splunk Add-on for Cisco ISE allows a Splunk to hit directly to Cisco ISE API to block mac-address via custom alerting. You just need to fill in:
* URL of the Cisco ISE REST API
* Username
* Password
* The field that contain mac-address that want to block by Cisco ISE. Ussually it contain $result.fieldname$