Within the Splunk_CiscoISE App, Go to Settings -> Event Types
Create a new Event Type named "cisco-ise"
and its definition should be - sourcetype=cisco:ise:syslog eventtype=cisco-ise-*
Change the permissions to **Global* and RW privileges as needed
Now all the graphs should have data populated
... View more
Within the Splunk_CiscoISE App, Go to Settings -> Event Types
Create a new Event Type named "cisco-ise"
and its definition should be - sourcetype=cisco:ise:syslog eventtype=cisco-ise-*
Change the permissions to **Global* and RW privileges as needed
Now all the graphs should have data populated
... View more