System Statistics (Syslog - Cisco ISE)

Vendor Documentation

Log Fields and Parsing

This section details the log fields available in this log message type, along with values parsed for both LogRhythm Default and LogRhythm Default v2.0 policies. A value of "N/A" (not applicable) means that there is no value parsed for a specified log field.

Log Field

LogRhythm Default

LogRhythm Default v2.0

pri_num

N/A

N/A

time

N/A

N/A

IP address/hostname

N/A

N/A

cat_name

N/A

<vendorinfo>

msg_id

<object>

N/A

total_seg

N/A

N/A

seg_num

<tag2>

N/A

timestamp

N/A

N/A

sequence_num

N/A

N/A

msg_code

<vmid>

<vmid>
<tag1>

msg_sev

<severity>

<severity>

msg_class

N/A

<subject> 

msg_text

N/A

<action> 

ConfigVersionId

<version>

N/A

OperationCounters

N/A

N/A

SysStatsAcsProcessHealth

N/A

N/A

PID

<processid>

N/A

SysStatsUtilizationCpu

<rate>

N/A

SysStatsUtilizationNetwork

<sinterface>

N/A

rcvd

<bytesout>

N/A

sent

<bytesin>

N/A

SysStatsUtilizationMemory

N/A

N/A

SysStatsUtilizationDiskIO

N/A

N/A

SysStatsUtilizationDiskSpace

N/A

N/A

SysStatsUtilizationDiskSpace

N/A

N/A

AverageRadiusRequestLatency

<milliseconds>

N/A

AverageTacacsRequestLatency

N/A

N/A

DeltaRadiusRequestCount

<quantity>

N/A

DeltaTacacsRequestCount

N/A

N/A

SysStatsUtilizationLoadAvg

N/A

N/A

SysStatsCpuCount

N/A

N/A

SysStatsProcessMemoryMB

N/A

N/A

ActiveSessionCount

N/A

N/A

Key1

N/A

N/A

Key2

N/A

N/A

Log Processing Settings

This section details log processing changes made from the LogRhythm Default policy to LogRhythm Default v2.0. In some cases, base rules are broken down into sub-rules to appropriately parse log message types by their event types.

LogRhythm Default

Regex ID

Rule Name

Rule Type

Common Event

Classification

1003098

System Statistics

Base Rule

Performance Statistics

Information

ISE Process Health

Sub Rule

System Statistics

Information

ISE Utilization

Sub Rule

System Statistics

Information

LogRhythm Default v2.0

Regex ID

Rule Name

Rule Type

Common Event

Classification

1012652

V 2.0 System Statistics Event

Base Rule

System Statistics

Information

V 2.0 EVID 70000 ISE Utilization

Sub Rule

General Information Log Message

Information

V 2.0 EVID 70001 ISE Process Health

Sub Rule

General Process Information

Information

V 2.0 EVID 70002 ISE Process Health Unavailable

Sub Rule

General Process Information

Information

V 2.0 EVID 70010 OCSP Statistics

Sub Rule

General Information Log Message

Information

V 2.0 EVID 70011 ISE Counters

Sub Rule

General Information Log Message

Information