Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Cisco ISE Function Not Working #11363

Open
macna opened this issue Oct 30, 2024 · 4 comments
Open

Cisco ISE Function Not Working #11363

macna opened this issue Oct 30, 2024 · 4 comments
Assignees
Labels
Parser Parser specialty review needed

Comments

@macna
Copy link

macna commented Oct 30, 2024

Describe the bug
The "CiscoISEEvent" function included with the Cisco ISE solution parses the data incorrectly, resulting in data appearing in the incorrect columns.

To Reproduce
Steps to reproduce the behavior:

  1. Go to Sentinel or Log Analytics
  2. Attempt to perform a search using the "CiscoISEEvent" function.
  3. See error

Expected behavior
Data to be returned in the correct columns.

Screenshots
Image

Desktop (please complete the following information):

  • OS: Windows 11
  • Browser: Edge
  • Version: 130.0.2849.46

Additional context
I believe this to be the same issue as #10070

@v-sudkharat
Copy link
Contributor

Hi @macna, Did you follow this step as well? - #10070 (comment)
If not, can you check with setting in Cisco side. Thanks!

@macna
Copy link
Author

macna commented Nov 4, 2024

Hi @v-sudkharat - we've checked the configuration in ISE and those options are enabled, as are several others. Are only certain categories supported by this parser?

@v-sudkharat v-sudkharat added the Parser Parser specialty review needed label Nov 6, 2024
@v-sudkharat
Copy link
Contributor

@macna, can you send the logs in below mail ID to check the format: [email protected]

@v-sudkharat
Copy link
Contributor

@macna, Waiting for logs to check on this issue. Thanks!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Parser Parser specialty review needed
Projects
None yet
Development

No branches or pull requests

3 participants