Hi,
In our company, we are also having the same issue. Using Splunk to collect the syslog from ISE, but no authentication information is collected.
And search the following information, it is missing as well.
eventtype=cisco-ise-failed-authentication
sourcetype=Cisco:ISE:Syslog auth
Can anyone help ?
... View more