icon/x Created with Sketch.

Splunk Cookie Policy

We use our own and third-party cookies to provide you with a great online experience. We also use these cookies to improve our products and services, support our marketing campaigns, and advertise to you on our website and other websites. Some cookies may continue to collect information after you have left our website. Learn more (including how to update your settings) here.
Accept Cookie Policy

We are working on something new...

A Fresh New Splunkbase
We are designing a New Splunkbase to improve search and discoverability of apps. Check out our new and improved features like Categories and Collections. New Splunkbase is currently in preview mode, as it is under active development. We welcome you to navigate New Splunkbase and give us feedback.

Accept License Agreements

Thank You

Downloading Cisco ISE
SHA256 checksum (cisco-ise_310.tgz) 102b0894ca737bb3e1ae296ff087a4c387c8b07a2374a33ef51f5952cccc3e18 SHA256 checksum (cisco-ise_302.tgz) a859703337bb95d1a0639e5b9fbdff6cb81a72a7e40514a3cd8e49ab612f6b60 SHA256 checksum (cisco-ise_301.tgz) 97ca686b2ad59c28d1525f729bb7e5d7d9e664ee0ad05019d435034f2aede62e SHA256 checksum (cisco-ise_300.tgz) a3c61d5899958681f94795060390047708f4d9753be84b4a0a5dbf47a7ff1627 SHA256 checksum (cisco-ise_205.tgz) 0be5bc7934fcf4cafa9afa000d5767af678a0d5dbd8143e11adbcaf4dae70b60 SHA256 checksum (cisco-ise_1217.tgz) 928a0191517070e021c6768d1403092cc2095de594c06d4c90bffa6c8cc6bc60

Flag As Inappropriate

soar

Cisco ISE

Splunk SOAR Cloud
Splunk Built
Overview
This app implements investigative and containment actions on a Cisco ISE device

Supported Actions Version 3.1.0

  • test connectivity: Validate the asset configuration for connectivity. This action logs into the device using a REST API call to check the connection and credentials
  • list endpoints: List the endpoints configured on the system
  • get device info: Get information about a specific endpoint
  • update device info: Update information or attributes for a specific endpoint
  • list sessions: List the sessions currently available on the Monitoring node
  • terminate session: Terminate sessions
  • list resources: Lists all the resources configured on the system of a particular resource
  • get resources: Get the information about resource if resource_id is provided. Fetch the list of resources match with the key-value filter
  • delete resource: Delete a resource
  • create resource: Create a resource
  • update resource: Update a resource
  • apply policy: Apply policy on selected Ip address or MAC address
  • clear policy: Clear policy on selected Ip address or MAC address
  • list policies: Lists all the ANC policies available
  • add policy: Add a new ANC Policy
  • delete policy: Delete a policy

Supported Actions Version 3.0.2

  • test connectivity: Validate the asset configuration for connectivity. This action logs into the device using a REST API call to check the connection and credentials
  • list endpoints: List the endpoints configured on the system
  • get device info: Get information about a specific endpoint
  • update device info: Update information or attributes for a specific endpoint
  • list sessions: List the sessions currently available on the Monitoring node
  • terminate session: Terminate sessions
  • list resources: Lists all the resources configured on the system of a particular resource
  • get resources: Get the information about resource if resource_id is provided. Fetch the list of resources match with the key-value filter
  • delete resource: Delete a resource
  • create resource: Create a resource
  • update resource: Update a resource
  • apply policy: Apply policy on selected Ip address or MAC address
  • clear policy: Clear policy on selected Ip address or MAC address
  • list policies: Lists all the ANC policies available
  • add policy: Add a new ANC Policy
  • delete policy: Delete a policy

Supported Actions Version 3.0.1

  • test connectivity: Validate the asset configuration for connectivity. This action logs into the device using a REST API call to check the connection and credentials
  • list endpoints: List the endpoints configured on the system
  • get device info: Get information about a specific endpoint
  • update device info: Update information or attributes for a specific endpoint
  • list sessions: List the sessions currently available on the Monitoring node
  • terminate session: Terminate sessions
  • list resources: Lists all the resources configured on the system of a particular resource
  • get resources: Get the information about resource if resource_id is provided. Fetch the list of resources match with the key-value filter
  • delete resource: Delete a resource
  • create resource: Create a resource
  • update resource: Update a resource
  • apply policy: Apply policy on selected Ip address or MAC address
  • clear policy: Clear policy on selected Ip address or MAC address
  • list policies: Lists all the ANC policies available
  • add policy: Add a new ANC Policy
  • delete policy: Delete a policy

Supported Actions Version 3.0.0

  • test connectivity: Validate the asset configuration for connectivity. This action logs into the device using a REST API call to check the connection and credentials
  • list endpoints: List the endpoints configured on the system
  • get device info: Get information about a specific endpoint
  • update device info: Update information or attributes for a specific endpoint
  • list sessions: List the sessions currently available on the Monitoring node
  • terminate session: Terminate sessions
  • list resources: Lists all the resources configured on the system of a particular resource
  • get resources: Get the information about resource if resource_id is provided. Fetch the list of resources match with the key-value filter
  • delete resource: Delete a resource
  • create resource: Create a resource
  • update resource: Update a resource
  • apply policy: Apply policy on selected Ip address or MAC address
  • clear policy: Clear policy on selected Ip address or MAC address
  • list policies: Lists all the ANC policies available
  • add policy: Add a new ANC Policy
  • delete policy: Delete a policy

Supported Actions Version 2.0.5

  • test connectivity: Validate the asset configuration for connectivity. This action logs into the device using a REST API call to check the connection and credentials
  • list endpoints: List the endpoints configured on the system
  • get device info: Get information about a specific endpoint
  • update device info: Update information or attributes for a specific endpoint
  • list sessions: List the sessions currently available on the Monitoring node
  • quarantine device: Quarantine the device
  • unquarantine device: Unquarantine the device
  • terminate session: Terminate sessions
  • list resources: Lists all the resources configured on the system of a particular resource
  • get resources: Get the information about resource if resource_id is provided. Fetch the list of resources match with the key-value filter
  • delete resource: Delete a resource
  • create resource: Create a resource
  • update resource: Update a resource
  • apply policy: Apply policy on selected Ip address or MAC address
  • clear policy: Clear policy on selected Ip address or MAC address

Supported Actions Version 1.2.17

  • test connectivity: Validate the asset configuration for connectivity. This action logs into the device using a REST API call to check the connection and credentials.
  • list sessions: List the sessions currently available on the Monitoring node.
  • quarantine device: Quarantine the device
  • unquarantine device: Unquarantine the device
  • terminate session: Terminate sessions

Release Notes

Version 3.1.0
June 13, 2024
  • Fixed pagination logic for 'list resources' action [PAPP-33229]
Version 3.0.2
Dec. 22, 2023
  • Updated requests and certifi dependencies in order to use platform packages [PAPP-30822,PAPP-31096]
Version 3.0.1
March 12, 2022
  • Minor fix in app documentation
Version 3.0.0
March 4, 2022
  • Added support for 'add policy', 'delete policy' and 'list policies' action. [PAPP-22978]
  • Removed 'quarantine system' and 'unquarantine system' actions. [PAPP-23977]
  • Changed asset configuration to support 'MnT Admin' and 'ERS Admin' admin groups in admin credentials. [PAPP-24134]
  • Updated documentation for the app
Version 2.0.5
Dec. 22, 2021

Cisco ISE Release Notes - Published by Phantom December 21, 2021

Version 2.0.5 - Released December 21, 2021

  • Compatibility changes for Python 3 support [PAPP-19196]
  • Add new optional asset configuration parameters 'ers_user' and 'ers_password'
  • Add new optional asset configuration parameter 'ha_device' for secondary node [PAPP-21216]
  • Updated logo for the app
  • Updated documentation for the app [PAPP-9112]
  • Added support for the below mentioned actions:
    • list resources [PAPP-8694]
    • get resources [PAPP-8693]
    • create resource [PAPP-8697]
    • update resource [PAPP-8695]
    • delete resource [PAPP-8696]
    • apply policy
    • clear policy
    • list endpoints
    • get device info
    • update device info
Version 1.2.17
Sept. 21, 2021

Cisco ISE Release Notes - Published by Phantom February 07, 2018

Version 1.2.17 - Released February 07, 2018

  • App action views and Logo updates

Subscribe Share

Are you a developer?

As a Splunkbase app developer, you will have access to all Splunk development resources and receive a 10GB license to build an app that will help solve use cases for customers all over the world. Splunkbase has 1000+ apps from Splunk, our partners and our community. Find an app for most any data source and user need, or simply create your own with help from our developer portal.

Follow Us:
Splunk, Splunk>,Turn Data Into Doing, Data-to-Everything, and D2E are trademarks or registered trademarks of Splunk Inc. in the United States and other countries. All other brand names,product names,or trademarks belong to their respective owners.