Hub
Identity

Cisco ISE 3.4 Administrative Audit Syslog

Cisco ISE CISE_Administrative_and_Operational_Audit remote syslog and matching ECS-style JSON for one Policy Administration Node, with the complete syslog record in event.original, for detections on ISE administrator activity. Logins, logoffs and failed logins of five administrators and 120 read-only operators, and logging-configuration changes; not RADIUS or TACACS traffic. Weekly episodes show an administrator account taken over by password guessing and used to switch off log forwarding.

Quick Start

uv tool install eventum-generator
git clone https://github.com/eventum-generator/content-packs.git
cd content-packs
eventum generate \
  --path generators/identity-cisco-ise/generator.yml \
  --id identity-cisco-ise \
  --live-mode true

Event Types

Event IDDescriptionFrequencyCategory
51001Administrator login succeeded48.4% measured shareiam, authentication
51002Administrator logged off48.4% measured shareiam, authentication
51000Administrator login failed2.2% measured sharenone
52001 UPSCategoryConfiguration changed: logging category severity change, disable or enable0.85% measured shareiam, configuration
52001 UPSLogTargetConfiguration changed: remote target status ENABLED/DISABLED0.06% measured shareiam, configuration

Realism Features

  • About 2,640 records a day on a fixed UTC curve: 30 an hour round the clock, 60 at 06-07 and 18-21, 120 at 07-08 and 17-18, and 210 at 08-17. Weekdays and weekends look the same.
  • Five full-access GUI administrators, each with an own workstation address, log in about 47 times a day together; 120 read-only operators (network operations and help desk) look up endpoints and live logs but change no configuration. Sessions of different accounts interleave, and each account has at most one session at a time. Operators sign in from the shared jump host in 10% of sessions, administrators in 15% of ordinary and 80% of logging-maintenance sessions.
  • A session may begin with one to four mistyped passwords, one failure being more common than two. Administrators mistype more often on the jump host (8.5% of sessions) than on their own workstation (2.8%), operators in 3% of sessions. Accounts sometimes give up after failures, consecutive failures stay below the lockout threshold of five, and failed logins are about 4% of all login attempts. Retries after a failure are a median of about 32 seconds apart, longer at night.
  • Ordinary administrator sessions hold zero to three logging-category edits before the logout: a severity change, a disable with targets cleared, or re-enabling a disabled category. About 6% of administrator sessions are logging maintenance that disables a category, in a quarter of them also detaches a remote target, and re-enables each object in 60% of cases. Remote targets change only in these sessions, about five disables a week, and a disabled target is usually restored within minutes (median about 4 minutes), a category within hours. Categories change more often than on a typical production node, about seven disables a day.
  • The stream is received by a separate, always-enabled AuditCollector (LOCAL6/NOTICE, 1,024-byte limit, escaped delimiters), so disabling RemoteCollector or BackupCollector does not cut it off. Message number and payload sequence advance together by one plus a random count of other audit records, keeping the per-node offset of the raw fixtures; ConfigVersionId advances with every edit and with occasional other deployment changes. AdminGUI_Session is the captured literal, not a unique session ID.
  • Background contains every part of the chain: repeated failures of one account within minutes, failure runs of three or four, give-ups, logins after failures, and maintenance sessions that disable a category and then a remote target. Only the complete ordered chain of one administrator and address within 30 minutes is absent. With anomaly_mode true, counts of these chain parts are about one per episode higher.
  • No complete ISE 3.4 appliance capture was obtained: login, logout, failure and UPSCategory shapes follow Elastic raw fixtures of unspecified version, the UPSLogTarget payload follows Cisco ISE 3.1 Common Criteria guidance, and the inverse enable form and other severities are extrapolated. Only codes 51000, 51001, 51002 and 52001 are emitted, observer.version is profile context, and rates, the hour curve, the account pools and the initial enabled state are scenario assumptions. Concurrent sessions of one account are not modeled.

Sample Output

{
  "@timestamp": "2026-09-01T12:55:38.182+00:00",
  "cisco_ise": {
    "log": {
      "admin": {
        "interface": "GUI"
      },
      "category": {
        "name": "CISE_Administrative_and_Operational_Audit"
      },
      "config_change": {
        "data": "Object modified:\\,Port = 514\\,IP Address = 10.40.0.20\\,Facility Code = LOCAL6\\,Length = 1024\\,Description = Remote UDP Collector\\,Include Alarms = FALSE\\,Old status = ENABLED New status = DISABLED\\,"
      },
      "config_version": {
        "id": 1277
      },
      "failure": {
        "flag": false
      },
      "message": {
        "code": "52001",
        "description": "Configuration-Changes: Changed configuration",
        "id": "0000185982"
      },
      "object": {
        "name": "RemoteCollector",
        "type": "UPSLogTarget"
      },
      "operation_message": {
        "text": "LoggingTargets \"RemoteCollector\" has been edited successfully."
      },
      "request_response": {
        "type": "initial"
      },
      "segment": {
        "number": 0,
        "total": 1
      }
    }
  },
  "client": {
    "ip": "10.99.2.41",
    "user": {
      "name": "secops"
    }
  },
  "ecs": {
    "version": "8.17.0"
  },
  "event": {
    "action": "configuration-changes",
    "category": [
      "iam",
      "configuration"
    ],
    "code": "52001",
    "dataset": "cisco_ise.log",
    "kind": "event",
    "original": "\u003c181\u003eSep  1 12:55:38 ise-01.corp.example CISE_Administrative_and_Operational_Audit 0000185982 1 0 2026-09-01 12:55:38.182 +00:00 0000186009 52001 NOTICE Configuration-Changes: Changed configuration, ConfigVersionId=1277, FailureFlag=false, RequestResponseType=initial, AdminInterface=GUI, AdminIPAddress=10.99.2.41, AdminName=secops, ConfigChangeData=Object modified:\\,Port = 514\\,IP Address = 10.40.0.20\\,Facility Code = LOCAL6\\,Length = 1024\\,Description = Remote UDP Collector\\,Include Alarms = FALSE\\,Old status = ENABLED New status = DISABLED\\,, ObjectType=UPSLogTarget, ObjectName=RemoteCollector, OperationMessageText=LoggingTargets \"RemoteCollector\" has been edited successfully.,",
    "sequence": 186009,
    "timezone": "+00:00",
    "type": [
      "change",
      "info"
    ]
  },
  "host": {
    "hostname": "ise-01.corp.example"
  },
  "log": {
    "level": "notice",
    "syslog": {
      "priority": 181,
      "severity": {
        "name": "notice"
      }
    }
  },
  "message": "2026-09-01 12:55:38.182 +00:00 0000186009 52001 NOTICE Configuration-Changes: Changed configuration, ConfigVersionId=1277, FailureFlag=false, RequestResponseType=initial, AdminInterface=GUI, AdminIPAddress=10.99.2.41, AdminName=secops, ConfigChangeData=Object modified:\\,Port = 514\\,IP Address = 10.40.0.20\\,Facility Code = LOCAL6\\,Length = 1024\\,Description = Remote UDP Collector\\,Include Alarms = FALSE\\,Old status = ENABLED New status = DISABLED\\,, ObjectType=UPSLogTarget, ObjectName=RemoteCollector, OperationMessageText=LoggingTargets \"RemoteCollector\" has been edited successfully.,",
  "observer": {
    "name": "ise-01.corp.example",
    "product": "Identity Services Engine",
    "vendor": "Cisco",
    "version": "3.4"
  },
  "related": {
    "hosts": [
      "ise-01.corp.example"
    ],
    "ip": [
      "10.99.2.41"
    ],
    "user": [
      "secops"
    ]
  },
  "user": {
    "name": "secops"
  }
}

Parameters

ParameterDefaultDescription
ise_nameise-01.corp.examplePAN hostname in the syslog header
admins[iseops, admin, netadmin, secops, helpdesk-l2]Full-access GUI administrator accounts (chain actors)
admin_ips[10.40.1.20, 10.40.1.21, 10.40.1.22, 10.40.1.23, 10.40.1.24]Workstation address of each administrator
admin_weights[32, 26, 20, 13, 9]Relative session rate of each administrator
jump_host_ip10.99.2.41Shared jump host (administrators: 15% of ordinary and 80% of maintenance sessions; operators: 10%)
remote_collector_ip10.40.0.20Address of RemoteCollector
backup_collector_ip10.40.0.21Address of BackupCollector
anomaly_interval_hours168Episode interval (weekly), at least 2 hours
anomaly_modetrueAdd anomaly episodes; false emits background only

Related Generators