Cisco ISE Attribute Reference
This reference lists the attributes that Device Security collects from Cisco ISE,
their names as stored in Device Security, and the Device Security fields they map to.
When
Device Security integrates with Cisco ISE, it imports network
access control data to support policy enforcement. The attributes in this reference
cover endpoint records, ERS (Endpoint Registration Service) attributes, and active
session data.
The third-party attribute name in Device Security refers to the attribute name
as it appears in the Assets Inventory table and in Query Engine. This follows the format
of third-party-name.attribute-name.
When viewing the attribute name in the Assets Inventory table column selector or on a
Device Details page, where the third-party name can be found as a header for the
attributes section, then the third-party name is removed from the attribute name.
For example, micrsoft_defender_xdr.macAddress would appear in the
Query Builder and in the Assets Inventory table, but under , the attribute would appear as macAddress.
Endpoint Attributes
Device Security collects endpoint attributes from Cisco ISE. The following table lists each Cisco ISE attribute, its name as stored in Device Security, and the Device Security field it maps to (if applicable).
Cisco ISE Attribute | Device Security Attribute Name | Device Security Common Attribute* | Description |
description | cisco_ise.description | Description | Description |
name | cisco_ise.name | hostname | Name of the device |
ipAddress | cisco_ise.ipAddress | IP Address | IP address |
mac | cisco_ise.mac | MAC Address; id | MAC address |
serialNumber | — | Serial Number | Serial number |
vendor | cisco_ise.vendor | Vendor | Device vendor |
assetConnectedLinks | cisco_ise.assetConnectedLinks | — | Asset connected links |
assetDeviceType | cisco_ise.assetDeviceType | — | Asset device type |
assetId | cisco_ise.assetId | — | Asset ID |
assetIpAddress | cisco_ise.assetIpAddress | — | Asset IP address |
assetName | cisco_ise.assetName | — | Asset name |
assetProductId | cisco_ise.assetProductId | — | Asset product ID |
assetProtocol | cisco_ise.assetProtocol | — | Asset protocol |
assetSerialNumber | cisco_ise.assetSerialNumber | — | Asset serial number |
assetSwRevision | cisco_ise.assetSwRevision | — | Asset sw revision |
assetVendor | cisco_ise.assetVendor | — | Asset vendor |
customAttributes | cisco_ise.customAttributes | — | Custom attributes |
deviceType | cisco_ise.deviceType | — | Device type |
groupId | cisco_ise.groupId | — | Group ID |
groupName | cisco_ise.groupName | — | Group name |
hardwareRevision | cisco_ise.hardwareRevision | — | Hardware revision |
id | cisco_ise.id | — | Unique identifier |
identityStore | cisco_ise.identityStore | — | Identity store |
identityStoreId | cisco_ise.identityStoreId | — | Identity store ID |
mdmAttributes | cisco_ise.mdmAttributes | — | Mdm attributes |
portalUser | cisco_ise.portalUser | — | Portal user |
productId | cisco_ise.productId | — | Product ID |
profileId | cisco_ise.profileId | — | Profile ID |
profileName | cisco_ise.profileName | — | Profile name |
protocol | cisco_ise.protocol | — | Protocol |
softwareRevision | cisco_ise.softwareRevision | — | Software revision |
staticGroupAssignment | cisco_ise.staticGroupAssignment | — | Static group assignment |
staticGroupAssignmentDefined | cisco_ise.staticGroupAssignmentDefined | — | Static group assignment defined |
staticProfileAssignment | cisco_ise.staticProfileAssignment | — | Static profile assignment |
staticProfileAssignmentDefined | cisco_ise.staticProfileAssignmentDefined | — | Static profile assignment defined |
Endpoint Session Attributes
Device Security collects endpoint session attributes from Cisco ISE. The following table lists each Cisco ISE attribute, its name as stored in Device Security, and the Device Security field it maps to (if applicable).
Cisco ISE Attribute | Device Security Attribute Name | Device Security Common Attribute* | Description |
mac | cisco_ise.mac | id | MAC address |
Session Attributes
Device Security collects session attributes from Cisco ISE. The following table lists each Cisco ISE attribute, its name as stored in Device Security, and the Device Security field it maps to (if applicable).
Cisco ISE Attribute | Device Security Attribute Name | Device Security Common Attribute* | Description |
orig_calling_station_id | — | id | Orig calling station ID |
device_ip_address | cisco_ise.device_ip_address | IP Address | Device IP address |
acs_server | cisco_ise.acs_server | — | Acs server |
auth_acs_timestamp | cisco_ise.auth_acs_timestamp | — | Auth acs timestamp |
auth_id | cisco_ise.auth_id | — | Auth ID |
authentication_method | cisco_ise.authentication_method | — | Authentication method |
authentication_protocol | cisco_ise.authentication_protocol | — | Authentication protocol |
calling_station_id | cisco_ise.calling_station_id | — | Calling station ID |
destination_ip_address | cisco_ise.destination_ip_address | — | Destination IP address |
device_type | cisco_ise.device_type | — | Device type |
endpoint_policy | cisco_ise.endpoint_policy | — | Endpoint policy |
identity_store | cisco_ise.identity_store | — | Identity store |
location | cisco_ise.location | — | Location |
network_device_name | cisco_ise.network_device_name | — | Network device name |
posture_status | cisco_ise.posture_status | — | Posture status |
selected_azn_profiles | cisco_ise.selected_azn_profiles | — | Selected azn profiles |
user_name | cisco_ise.user_name | — | User name |
Wired Session Attributes
Device Security collects wired session attributes from Cisco ISE. The following table lists each Cisco ISE attribute, its name as stored in Device Security, and the Device Security field it maps to (if applicable).
Cisco ISE Attribute | Device Security Attribute Name | Device Security Common Attribute* | Description |
user_name | cisco_ise.user_name | AD Username | User name |
framed_ip_address | cisco_ise.framed_ip_address | IP Address | Framed IP address |
acs_timestamp | cisco_ise.acs_timestamp | Last Activity | Acs timestamp |
location | cisco_ise.location | Location | Location |
calling_station_id | cisco_ise.calling_station_id | MAC Address; id | Calling station ID |
nas_ip_address | cisco_ise.nas_ip_address | Switch IP | NAS IP address |
connected_device_mac | cisco_ise.connected_device_mac | Switch MAC | MAC address of the connected device |
nas_port_id | cisco_ise.nas_port_id | Switch Port | Nas port ID |
network_device_name | cisco_ise.network_device_name | switch_name | Network device name |
acct_session_id | cisco_ise.acct_session_id | — | Acct session ID |
acs_server | cisco_ise.acs_server | — | Acs server |
asset_category | cisco_ise.asset_category | — | Asset category |
asset_description | cisco_ise.asset_description | — | Asset description |
audit_session_id | cisco_ise.audit_session_id | — | Audit session ID |
auth_acs_timestamp | cisco_ise.auth_acs_timestamp | — | Auth acs timestamp |
auth_id | cisco_ise.auth_id | — | Auth ID |
authentication_method | cisco_ise.authentication_method | — | Authentication method |
authentication_protocol | cisco_ise.authentication_protocol | — | Authentication protocol |
authorization_rule | cisco_ise.authorization_rule | — | Authorization rule |
cts_security_group | cisco_ise.cts_security_group | — | Cts security group |
deployment_stage | cisco_ise.deployment_stage | — | Deployment stage |
destination_ip_address | cisco_ise.destination_ip_address | — | Destination IP address |
device_ip_address | cisco_ise.device_ip_address | — | Device IP address |
device_type | cisco_ise.device_type | — | Device type |
endpoint_policy | cisco_ise.endpoint_policy | — | Endpoint policy |
failed | cisco_ise.failed | — | Failed |
identity_group | cisco_ise.identity_group | — | Identity group |
identity_store | cisco_ise.identity_store | — | Identity store |
is_wireless | cisco_ise.is_wireless | — | Is wireless |
ise_policy_set | cisco_ise.ise_policy_set | — | Ise policy set |
logical_profile | cisco_ise.logical_profile | — | Logical profile |
message_code | cisco_ise.message_code | — | Message code |
nas_port_type | cisco_ise.nas_port_type | — | NAS port type |
network_device_profile | cisco_ise.network_device_profile | — | Network device profile |
passed | cisco_ise.passed | — | Passed |
posture_status | cisco_ise.posture_status | — | Posture status |
response_time | cisco_ise.response_time | — | Response time |
selected_azn_profiles | cisco_ise.selected_azn_profiles | — | Selected azn profiles |
server | cisco_ise.server | — | Server |
service_type | cisco_ise.service_type | — | Service type |
Wireless Session Attributes
Device Security collects wireless session attributes from Cisco ISE. The following table lists each Cisco ISE attribute, its name as stored in Device Security, and the Device Security field it maps to (if applicable).
Cisco ISE Attribute | Device Security Attribute Name | Device Security Common Attribute* | Description |
user_name | cisco_ise.user_name | AD Username | User name |
location | cisco_ise.location | AP Location; Location | Location |
nas_ip_address | cisco_ise.nas_ip_address | ap_ip | NAS IP address |
connected_device_mac | cisco_ise.connected_device_mac | ap_mac | MAC address of the connected device |
framed_ip_address | cisco_ise.framed_ip_address | IP Address | Framed IP address |
acs_timestamp | cisco_ise.acs_timestamp | Last Activity | Acs timestamp |
calling_station_id | cisco_ise.calling_station_id | MAC Address; id | Calling station ID |
acct_session_id | cisco_ise.acct_session_id | — | Acct session ID |
acs_server | cisco_ise.acs_server | — | Acs server |
asset_category | cisco_ise.asset_category | — | Asset category |
asset_description | cisco_ise.asset_description | — | Asset description |
audit_session_id | cisco_ise.audit_session_id | — | Audit session ID |
auth_acs_timestamp | cisco_ise.auth_acs_timestamp | — | Auth acs timestamp |
auth_id | cisco_ise.auth_id | — | Auth ID |
authentication_method | cisco_ise.authentication_method | — | Authentication method |
authentication_protocol | cisco_ise.authentication_protocol | — | Authentication protocol |
authorization_rule | cisco_ise.authorization_rule | — | Authorization rule |
cts_security_group | cisco_ise.cts_security_group | — | Cts security group |
deployment_stage | cisco_ise.deployment_stage | — | Deployment stage |
destination_ip_address | cisco_ise.destination_ip_address | — | Destination IP address |
device_ip_address | cisco_ise.device_ip_address | — | Device IP address |
device_type | cisco_ise.device_type | — | Device type |
endpoint_policy | cisco_ise.endpoint_policy | — | Endpoint policy |
failed | cisco_ise.failed | — | Failed |
identity_group | cisco_ise.identity_group | — | Identity group |
identity_store | cisco_ise.identity_store | — | Identity store |
is_wireless | cisco_ise.is_wireless | — | Is wireless |
ise_policy_set | cisco_ise.ise_policy_set | — | Ise policy set |
logical_profile | cisco_ise.logical_profile | — | Logical profile |
message_code | cisco_ise.message_code | — | Message code |
nas_port_id | cisco_ise.nas_port_id | — | Nas port ID |
nas_port_type | cisco_ise.nas_port_type | — | NAS port type |
network_device_name | cisco_ise.network_device_name | — | Network device name |
network_device_profile | cisco_ise.network_device_profile | — | Network device profile |
passed | cisco_ise.passed | — | Passed |
posture_status | cisco_ise.posture_status | — | Posture status |
response_time | cisco_ise.response_time | — | Response time |
selected_azn_profiles | cisco_ise.selected_azn_profiles | — | Selected azn profiles |
server | cisco_ise.server | — | Server |
service_type | cisco_ise.service_type | — | Service type |
* Only some attributes map to a Device Security Common Attribute.