> Source: [sk172608](https://support.checkpoint.com/results/sk/sk172608)

# sk172608 - Identity Collector ignores 'POSTURED' login events

| Property | Value |
|----------|-------|
| Solution ID | sk172608 |
| Date Created | 2021-03-18 |
| Last Modified | 2025-05-11 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20, R81.10 (EOS), R81 (EOS) |
| OS | Windows |

## Symptoms

- * After enabling Cisco ISE Posturing service, Identity Collector stops accepting user information.
* The `a_ise_extension.log` file contains the following log entries:
  * `IseSession::parseSession: Found state: POSTURED`
  * `IseSession::parseSession: ERROR: Unknown session state: POSTURED`
  * `GatheringManager::processSession: Session is null; no action will be taken`

  The log indicates that the system encountered an unknown session state "POSTURED" while processing the session. As a result, the `GatheringManager` is unable to perform any actions due to the null session.

## Cause

Identity Collector is designed to integrate with Cisco's ISE (Identity Services Engine) server. However, when the "Posture" service is activated on the ISE server, the Identity Collector encounters issues parsing the login events. This occurs because login events with the POSTURED status are not supported by Identity Collector versions R82.002.0000 and lower.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
