<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Stealthwatch setup and functionalities in Security Analytics</title>
    <link>https://community.cisco.com/t5/security-analytics/stealthwatch-setup-and-functionalities/m-p/3684063#M110</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;the fact that you don't see the full traffic from the main dashboard is normal: that is designed to show only active alarms.&lt;/P&gt;
&lt;P&gt;In order to use the java client, please click on Desktop Client (top right corner on the screenshot).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;From the webUI you can run Analyze-&amp;gt;Flow Search and run a query to see every flow recevied by the flow collector.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The contextual guide available in the help menu is the best guide I can suggest for the WebUI.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'll reply per points now:&lt;/P&gt;
&lt;P&gt;- It depends on what you'll need to do. If your role is security analyst probably not. If you need to manage any of the advanced features, than yes.&lt;/P&gt;
&lt;P&gt;- Contextual menu&lt;/P&gt;
&lt;P&gt;- UDP:2055 and TCP:443 if you point the flow sensor to the SMC (Management System configuration option). 2055 is the default port number. You can change it.&lt;/P&gt;
&lt;P&gt;- 60 days as per &lt;A href="https://www.cisco.com/c/dam/en/us/td/docs/security/stealthwatch/release_notes/SW_6_10_2_Release_Notes_DV_1_2.pdf" target="_blank"&gt;https://www.cisco.com/c/dam/en/us/td/docs/security/stealthwatch/release_notes/SW_6_10_2_Release_Notes_DV_1_2.pdf&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this helps.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Dario&lt;/P&gt;</description>
    <pubDate>Wed, 08 Aug 2018 12:44:10 GMT</pubDate>
    <dc:creator>dcavalla</dc:creator>
    <dc:date>2018-08-08T12:44:10Z</dc:date>
    <item>
      <title>Stealthwatch setup and functionalities</title>
      <link>https://community.cisco.com/t5/security-analytics/stealthwatch-setup-and-functionalities/m-p/3682898#M109</link>
      <description>&lt;P&gt;Hi;&lt;/P&gt;
&lt;P&gt;I'm working on Stealthwatch and to practice it's futures I downloaded the "Trial" virtual components (version 6.10.2) and installed/configured in this order:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;I installed Flow Collector virtual.&lt;/LI&gt;
&lt;LI&gt;I installed Management Console virtual.&lt;/LI&gt;
&lt;LI&gt;I created management channel between Flow Collector and Management Console.&lt;/LI&gt;
&lt;LI&gt;There was no Netflow capable device that I could use, so I had to install Flow Sensor virtual.&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;On Flow Sensor I added flow collector &amp;amp; management console IP addresses.&amp;nbsp;&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="s1.png" style="width: 721px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/16215i50658BE4AC24EA2C/image-size/large?v=v2&amp;amp;px=999" role="button" title="s1.png" alt="s1.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;6. Flow Sensor virtual had 2 interfaces, which I connect the first one to my management network and the 2nd interface to another standard vSwitch on my vSphere client. I Assigned a physical interface to that vSwitch and attached it to a SPAN port on the physical switch.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="s2.png" style="width: 567px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/16217i1F6EB57002294F2D/image-size/large?v=v2&amp;amp;px=999" role="button" title="s2.png" alt="s2.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;7. I changed the Promiscuous mode on the above port group (TFSensor) to "Accept".&amp;nbsp;&lt;/P&gt;
&lt;P&gt;8. The home page on the Flow Collector shows that I'm receiving flows.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="s3.png" style="width: 873px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/16218i84CA07C196F59C48/image-size/large?v=v2&amp;amp;px=999" role="button" title="s3.png" alt="s3.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;9. But I don't see any information on Management Console. I shows only 3 devices as this but nothing else.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="s4.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/16220i93F8DA31D4E8717D/image-size/large?v=v2&amp;amp;px=999" role="button" title="s4.png" alt="s4.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also I didn't managed to find "any" documents or user guides for the stealthwatch except ones currently are on the Cisco website which use SMC java client for version 6.9. But I only can see webUI which doesn't have to do anything to the menu structures of the SMC java client. So besides the issue that I mentioned up to this point,&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Do I need to use that client for version 6.10.2?&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;Where can I find SMC user guides for WebUI?&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;Does Flow Sensor communicate with Flow Collector through UDP:2055 ?&lt;/LI&gt;
&lt;LI&gt;What is the limitations of the Trial version?&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Tue, 20 Aug 2019 17:29:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/security-analytics/stealthwatch-setup-and-functionalities/m-p/3682898#M109</guid>
      <dc:creator>ciscoworlds</dc:creator>
      <dc:date>2019-08-20T17:29:56Z</dc:date>
    </item>
    <item>
      <title>Re: Stealthwatch setup and functionalities</title>
      <link>https://community.cisco.com/t5/security-analytics/stealthwatch-setup-and-functionalities/m-p/3684063#M110</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;the fact that you don't see the full traffic from the main dashboard is normal: that is designed to show only active alarms.&lt;/P&gt;
&lt;P&gt;In order to use the java client, please click on Desktop Client (top right corner on the screenshot).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;From the webUI you can run Analyze-&amp;gt;Flow Search and run a query to see every flow recevied by the flow collector.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The contextual guide available in the help menu is the best guide I can suggest for the WebUI.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'll reply per points now:&lt;/P&gt;
&lt;P&gt;- It depends on what you'll need to do. If your role is security analyst probably not. If you need to manage any of the advanced features, than yes.&lt;/P&gt;
&lt;P&gt;- Contextual menu&lt;/P&gt;
&lt;P&gt;- UDP:2055 and TCP:443 if you point the flow sensor to the SMC (Management System configuration option). 2055 is the default port number. You can change it.&lt;/P&gt;
&lt;P&gt;- 60 days as per &lt;A href="https://www.cisco.com/c/dam/en/us/td/docs/security/stealthwatch/release_notes/SW_6_10_2_Release_Notes_DV_1_2.pdf" target="_blank"&gt;https://www.cisco.com/c/dam/en/us/td/docs/security/stealthwatch/release_notes/SW_6_10_2_Release_Notes_DV_1_2.pdf&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this helps.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Dario&lt;/P&gt;</description>
      <pubDate>Wed, 08 Aug 2018 12:44:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/security-analytics/stealthwatch-setup-and-functionalities/m-p/3684063#M110</guid>
      <dc:creator>dcavalla</dc:creator>
      <dc:date>2018-08-08T12:44:10Z</dc:date>
    </item>
  </channel>
</rss>

