Hello Arunkumar,
Please follow this Technote for troubleshooting> https://www.ibm.com/support/pages/node/6326057
From experience, there might be another log source on the same event collecting host which is using the same port (517). This causes a port conflict and Traffic Analysis can get confused.
If you already have another log source type using port 517, just change the log source config to use a free port on the same eventcollector, e.g. 518/519/520 etc.
When you manually create the Cisco ISE log source, it should automatically create an Iptables rule to accept traffic.
The pre-routing rule method is only needed if it's not easy to target the Cisco ISE device to send to port 517, what the rule does is it listens for traffic from a certain source IP on port 514 and forwards it to port 517. Ref doc: https://www.ibm.com/docs/en/dsm?topic=sol-configuring-iptables-udp-multiline-syslog-events
Hope this is helpful, good luck!
-C-
------------------------------
Carl Mohn
IBM
Dublin
------------------------------