Configure inputs for the Splunk Add-on for Cisco ISE¶
You must configure Cisco ISE to send logs to Splunk Enterprise via syslog. To configure your appliance to send data to syslog, see Configure Cisco ISE to send logs to Splunk Enterprise.
For information on how to configure a Splunk forwarder or single-instance to receive a syslog input, see Get data from TCP and UDP ports in the Getting Data In manual.