
If the "Target Type" is TCP use Settings > Data Inputs > TCP > New Local TCP.Add the new port(s) in order to enable receiving logs into Splunk.Tune all other fields at your discretion.Port that you are using on the Splunk Enterprise system or port configured for TCP or UDP input on Splunk Connect for Syslog (SC4S) or syslog aggregator (for example, rsyslog, syslog-ng) as a network input.Įvents will be broken if you use a smaller value. IP address of the Splunk Enterprise system Target name, also used below in the category In Cisco ISE, choose Administration > System > Logging > Remote Logging Targets.The following sections provide detailed configuration instructions.įor more information, see the Logging section of the Cisco ISE User Guide. Add the target to the appropriate logging categories.To enable to Splunk Enterprise to receive data from your Cisco ISE remote system logging, complete these steps: Configure Cisco ISE to send logs to Splunk Enterprise for the Splunk Add-on for Cisco ISE
