ise_dc_view_threat_events
Returns threat event logs from various sources, filterable by severity, vendor, IP, or MAC address to identify and investigate security incidents in Cisco ISE.
Instructions
[Report] Threat Events: Log of threat events received from various sources Filterable columns include: LOGGED_AT, MAC_ADDRESS, IP_ADDRESS, ID, SEVERITY, TITLE, EVENT_TIME, VENDOR_NAME.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| limit | No | Max rows (default 100, max 10000). | |
| order_by | No | Column to sort by (prefix '-' for descending). | |
| days_back | No | Only rows from the last N days (uses the view's time column). | |
| filter_op | No | EQ=exact, CONTAINS/LIKE=substring, GT/LT/GTE/LTE=compare. | EQ |
| deployment | No | Target ISE deployment: name ('RADIUS Only'), slug ('radius-only'), or number ('1' or 'Deployment 1'). Omit to use the only/default deployment. Call ise_list_deployments to see the choices. | |
| filter_value | No | Value to match for the filter column. | |
| filter_column | No | Column to filter on (case-insensitive). |