Cisco ISE - any community action?

Content Packs for Cisco ISE?
Anyone aware of content packs for Cisco ISE Logs? I found some extractors but they are pretty old and certainly not complete - dubsout/graylog-cisco-ise: Cisco ISE Extractors for Graylog (github.com)

Also I read that using extractors is not the recommended approach anymore. So what I am looking for is Pipeline rules and maybe some dashboards.

I have found a big collection for Elastic Search here: integrations/packages/cisco_ise at main · elastic/integrations (github.com)

They are also talking abount pipelines but I assume it’s not the same concept?

Help?

Hey @riborg

Yeah, Graylog’s pipeline is the way to go, you have more control over modifying your logs, and less resources being used then Extractor/s.

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.