Cisco ISE Advanced Settings
Advanced Settings - Cisco ISE
Note
- Advanced settings can apply to either all connections of this adapter, or to a specific connection. For more detailed information, see Advanced Configuration for Adapters.
- For more general information about advanced settings, see Adapter Advanced Settings.
-
Fetch Internal Users - Select this option to fetch internal users.
-
Fetch Guest Users - Select this option to fetch guest users.
-
Fetch Admin Users - Select this option to fetch admin users.
-
Fetch endpoints (through ERS) - Select this option to fetch data from the ISE endpoint through the ERS endpoint API.
-
Enable ERS Authentication Status and Sessions enrichment for Endpoint devices (default: enabled) - Select this option to enable enrichment of ERS endpoint devices with authentication status and session data. When enabled, the following sub-settings become available:
- Enrich ERS Endpoints with Authentication Status (default: disabled) - Select this option to add authentication status data for each fetched endpoint.
- Enrich ERS Endpoints with Session details (default: enabled) - Select this option to fetch and enrich endpoint devices with session parameters from the ISE Monitoring (MnT) API, which allows you to populate the Last Seen field, for example. See ISE Monitoring API examples for reference.
Note
Enabling Enrich ERS Endpoints with Session details makes one API call per fetched endpoint to the ISE Monitoring (MnT) API. On large ISE deployments (hundreds of thousands of endpoints), this can significantly increase fetch duration.
- Session details level - Select the level of session detail to retrieve:
- Basic (default) - add basic session data.
- Detailed - retrieve detailed session data.
- Detailed with Custom Attributes - include session enrichment that uses custom attributes.
-
Enrich Endpoints with Policy Name - Select this option to enrich endpoint devices with the policy name.
-
Fail client on pxGrid connection error (default: true) - Select to propagate errors originating from the pxGrid connection when Use pxGrid to fetch live sessions is enabled for a client. When this is not set, errors are propagated only when there are errors from both pxGrid and ERS connectivity to a client.
Note
When configuring the Cisco ISE and you do not want to use the pxGrid fetch to retrieve the data, enable Fetch endpoints.
-
Skip devices without IP address - Select this option to not fetch devices that do not have an IP address.
-
Fetch Certificates - Select this option to fetch certificates.
-
Parse FismaID - Select this option to parse FismaID from selected Authorization Profiles.
-
Enable Custom Parsing - Enable this option to define how to parse specific fields from the raw data fetched. You can choose to parse the data into an already existing field, or create a new one. See Adapter Custom Parsing for more information.
-
Only include devices that have a name OR an IP address - Select this option to only fetch devices that have either an asset name or an IP address.
-
Only include devices that have a name AND an IP address - Select this option to only fetch devices that have both an asset name and an IP address.
Important
If a Cisco ISE connection has 'Fetch endpoints' enabled and at the same time has 'Skip devices without IP address' or 'Only include devices that have a name AND an IP address' enabled, then the endpoints data will not be ingested, because endpoints don't have IP address data.
Updated 6 days ago
