Cisco Cisco Identity Services Engine 1.2 产品宣传页
安全访问操作指南
检查
Splunk pxGrid 日志文件
日志文件可以位于“
/Applications/splunk/var/log/splunk/pxgridremediate.log”或 Splunk 的安装路径中。
下面的详细信息表明已通过
Splunk pxGrid_unQuarantine_by_IP 工作流程操作成功对终端取消隔离
2015-03-11 23:20:51,662 [016929] INFO root: Logger Initialized
2015-03-11 23:20:52,084 [016929] INFO root:
item=pxGrid1.lab6.com|test1|/Applications/Splunk/etc/apps/Splunk_TA_cisco-
ise/bin/certs/mac.jks|/Applications/Splunk/etc/apps/Splunk_TA_cisco-ise/bin/certs/caroot1.jks|
2015-03-11 23:20:52,084 [016929] INFO root: xgridHostname=pxGrid1.lab6.com
2015-03-11 23:20:52,084 [016929] INFO root: xgridUsername=test1
2015-03-11 23:20:52,084 [016929] INFO root:
keystoreFilename=/Applications/Splunk/etc/apps/Splunk_TA_cisco-ise/bin/certs/mac.jks
2015-03-11 23:20:52,084 [016929] INFO root:
truststoreFilename=/Applications/Splunk/etc/apps/Splunk_TA_cisco-ise/bin/certs/caroot1.jks
2015-03-11 23:20:52,411 [016929] INFO root: keystorePassword=<password />
2015-03-11 23:20:52,411 [016929] INFO root: truststorePassword=<password />
2015-03-11 23:20:52,411 [016929] INFO root: xgridAction=unquarantine
2015-03-11 23:20:52,411 [016929] INFO root: xgridType=ip
2015-03-11 23:20:52,411 [016929] INFO root: xgridTarget=10.0.0.17
2015-03-11 23:20:52,411 [016929] INFO root: LAUNCHING: java -jar
/Applications/Splunk/etc/apps/Splunk_TA_cisco-ise/bin/lib/pxGrid_Search.jar pxGrid1.lab6.com test1
/Applications/Splunk/etc/apps/Splunk_TA_cisco-ise/bin/certs/mac.jks cisco123
/Applications/Splunk/etc/apps/Splunk_TA_cisco-ise/bin/certs/caroot1.jks cisco123 10.0.0.17 unquarantine_ip
2015-03-11 23:21:08,792 [016929] INFO root: result from java cmd: 23:20:53.968 [Smack Listener Processor
(0)] DEBUG com.cisco.pxgrid.GridConnection - associate presence packet received (type=available,
from=test1@xgrid.cisco.com)23:21:00.132 [Thread-0] DEBUG c.c.p.internal.CapabilityManager - refreshing
connection state...
23:21:00.133 [Thread-0] DEBUG c.c.p.internal.CapabilityManager - done refreshing connection state.
23:21:00.134 [Thread-0] DEBUG c.c.p.i.s.NotificationHandlerSmack - refreshing connection state...
23:21:00.135 [Thread-0] DEBUG c.c.p.i.s.NotificationHandlerSmack - done refreshing connection state.
23:21:00.390 [main] DEBUG c.c.p.internal.CapabilityManager - subscribed
(topic=EndpointProtectionServiceCapability-1.0)
© 2015 思科系统公司
第
35 页