To configure log forwarding from Cisco ISE, use the Remote Logging Targets feature available in the ISE administration console. Follow the official Cisco documentation below for step-by-step setup instructions.
When configuring syslog, in the Remote Logging Targets screen, ensure the Comply to RFC 3164 option is checked. This ensures logs are forwarded in the RFC 3164 syslog format required by Scope.

The Scope application supports ingestion of Cisco ISE logs in the Syslog format.
<181>Feb 23 21:44:54 cisco-ise-host CISE_Passed_Authentications 0000000028 1 0 2021-02-23 21:44:54.276 +00:00 0000001707 5233 NOTICE Passed-Authentication: TrustSec Data Download Succeeded, ConfigVersionId=9, Device IP Address=10.2.69.144, DestinationIPAddress=10.2.69.144, DestinationPort=1645, UserName=#redact#, Protocol=Radius, RequestLatency=281, NetworkDeviceName=redact, User-Name=#redact#, NAS-IP-Address=10.2.69.144, NAS-Port=2, NAS-Port-Type=Virtual, cisco-av-pair=redact-environment-version=1, cisco-av-pair=redact-environment-data=redact, cisco-av-pair=redact-device-capability=env-data-fragment, cisco-av-pair=redact-pac-opaque=****, cisco-av-pair=coa-push=true, NetworkDeviceProfileName=Cisco, NetworkDeviceProfileId=8ade1f15-aef1-4a9a-8158-d02e835179db, IsThirdPartyDeviceFlow=false, AcsSessionID=ise/403491114/1, SelectedAccessService=NDAC_SGT_Service, Step=11001, Step=11017, Step=11117, Step=15012, Step=15036, Step=15006, Step=11002, NetworkDeviceGroups=Location#All Locations#dCloud, NetworkDeviceGroups=Device Type#All Device Types#Security Devices#VPN, AuthorizationPolicyMatchedRule=Default, CPMSessionID=c612851bJ4_5zUNfXSy7PCu6hSY3K1tPzLJOLXwVfJMIFdTrUjg, ISEPolicySetName=NetworkDeviceAuthorization, DTLSSupport=Unknown, Network Device Profile=Cisco, Location=Location#All Locations#dCloud, Device Type=Device Type#All Device Types#Security Devices#VPN, Response={Class=CACS:c612851bJ4_5zUNfXSy7PCu6hSY3K1tPzLJOLXwVfJMIFdTrUjg:ise/403491114/1; cisco-av-pair=redact:server-list=redactServerList1-0001; cisco-av-pair=redact:security-group-tag=0002-11; cisco-av-pair=redact:environment-data-expiry=86400; cisco-av-pair=redact:security-group-table=0001-46; }