Aug 28 2023 03:31 PM
Hi beloved community,
I have a default KQL below which is used to detect when Cisco ISE failed backup, it fires an alert in Sentinel.
But it is not working as expected - it does fire an alert, but with a timestamp only.
Nonetheless, I can see it is also supposed to return the hostname and IP of the device that actually triggered the '60095', '60098' events (failed backup).
CiscoISEEvent | where TimeGenerated > ago(lbtime) | where EventId in ('60095', '60098') | project TimeGenerated, DvcHostname, DvcIpAddr | extend HostCustomEntity = DvcHostname | extend IPCustomEntity = DvcIpAddr
I have further escalated this to our outsourced SOC where their engineers had a look and they had advised: We suspect that it has something to do with the Event ID that's been captured in the raw logs which are not giving enough information and I believe we don't have visibility on this. We suggest filing a ticket to Microsoft for further troubleshooting on the mentioned Event IDs.
I have tried some other KQL configs but none of them worked out in this regard.
I guess my question at this point would be is it still a KQL issue, or is it more of the actual log issue? (Coz those Cisco devices are managed by our MSPs, and we dont have visibility into them either)
Much appreciated for any directions so that I could dig further, as I am still a bit green on Sentinel.
Thanks in advance!
Below are from Cisco websites which elaborates their definition of the eventsIDs:
Message Code: 60095
Severity: ERROR
Message Text: ISE Backup has failed
Message Description: ISE Backup has failed
Local Target Message Format: <timestamp> <seq_num> 60095 ERROR System-Management: ISE Backup has failed, <log details>
Remote Target Message Format: <pri_num> <timestamp> <IP address/hostname> <CISE_logging category> <msg_id> <total seg> <seg num><timestamp> <seq_num> 60095 ERROR System-Management: ISE Backup has failed, <log details>
Message Code: 60098
Severity: ERROR
Message Text: ISE Log Backup has failed
Message Description: ISE Log Backup has failed
Local Target Message Format: <timestamp> <seq_num> 60098 ERROR System-Management: ISE Log Backup has failed, <log details>
Remote Target Message Format: <pri_num> <timestamp> <IP address/hostname> <CISE_logging category> <msg_id> <total seg> <seg num><timestamp> <seq_num> 60098 ERROR System-Management: ISE Log Backup has failed, <log details>
Sep 14 2023 09:43 PM
Sep 17 2023 04:07 PM
SolutionSep 17 2023 05:12 PM
Sep 17 2023 05:13 PM
Sep 17 2023 04:07 PM
Solution