Cisco ISE
You can integrate Cisco Identity Services Engine (ISE) with Sophos XDR so that it sends data to Sophos for analysis.
This page gives you an overview of the integration.
Cisco ISE product overview
Cisco Identity Services Engine (ISE) is a network access control (NAC) solution that authenticates, authorizes, profiles, and enforces policy for users and devices connecting to the network. It acts as the policy decision point in a zero-trust architecture, using RADIUS and TACACS+ to control network and device-administration access.
What we ingest
Sophos XDR collects Cisco ISE syslog data by listening for messages your ISE deployment forwards to a Sophos XDR data collector. The following log categories are collected:
- Authentication: RADIUS authentication events and administrator logins.
- Command authorization: TACACS+ device-administration command events.
Event and data types
We ingest the following event and data types from Cisco ISE:
- Authentication: RADIUS authentication events (passed and failed) and administrator sign-in events, with the user, device, and result. Normalized to authentication telemetry.
- Command authorization: TACACS+ device-administration command authorization events, including the command and user. Normalized to process telemetry.
Data provided by this integration
Data provided by Cisco ISE gets normalized to the following schemas:
authprocess
For more information about using schemas in Data Lake Search, see Schemas and logical types.