Refer to the official Cisco documentation below to configure log forwarding from Cisco ISE.
The Scope application supports ingestion of Cisco ISE logs in the Syslog format.
<181>Mar 3 11:37:34 cisco-ise-host CISE_Passed_Authentications 0000083423 1 0 2022-03-03 11:37:34.978 +00:00 0000083490 5200 NOTICE Passed-Authentication: Authentication succeeded, ConfigVersionId=1696, UserName=92-09-00-00-00-01, Protocol=Radius
<182>Mar 24 05:04:25 redacted03 CISE_MONITORING_DATA_PURGE_AUDIT 2025-03-24 04:11:26.056 -0400 60198 INFO null: MnT purge event occurred, MESSAGE=purging Tacacs data older than 22-FEB-25,
<180>Jul 9 07:15:00 aws-ise-redacted CISE_Alarm WARN: No Authentications in the last 15 minutes
<13> s27-isev02-f1 2024-10-22T17:38:43-04:00 s27-isev02-f1 CISE_Failed_Attempts 0011561880 1 0 2024-10-22 17:38:43.339 -04:00 0719771455 5440 NOTICE RADIUS: Endpoint abandoned EAP session and started new
<13> redact-ise01 2026-01-08T09:37:36-05:00 redact-ise01 CISE_Alarm INFO: EAP Connection Timeout : Server=redact-ise01; NAS IP Address=10.86.134.25; NAS Identifier=redact-CHN