<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco Secure Network Analytics - Custom Events not working towards in Security Analytics</title>
    <link>https://community.cisco.com/t5/security-analytics/cisco-secure-network-analytics-custom-events-not-working-towards/m-p/5257527#M1150</link>
    <description>&lt;P&gt;Okey. So what you are saying Is that It's not possible to create "Custom Security Events" towards NVM telemetry data?&lt;BR /&gt;My NVM-module configuration Is only for endpoints that are on a "trusted network".&lt;BR /&gt;&lt;BR /&gt;I actually got some hits today in my "Security Insight Dashboard" of yesterdays creation of my Custom Security Event.&lt;BR /&gt;But the alerts Is triggered on others endpoints that not even have the NVM-module installed which Is weird.&lt;BR /&gt;&lt;BR /&gt;Thanks&lt;/P&gt;</description>
    <pubDate>Thu, 06 Feb 2025 12:43:25 GMT</pubDate>
    <dc:creator>aleksta9826435</dc:creator>
    <dc:date>2025-02-06T12:43:25Z</dc:date>
    <item>
      <title>Cisco Secure Network Analytics - Custom Events not working towards NVM</title>
      <link>https://community.cisco.com/t5/security-analytics/cisco-secure-network-analytics-custom-events-not-working-towards/m-p/5257076#M1146</link>
      <description>&lt;P&gt;Hi all&lt;/P&gt;&lt;P&gt;Experiencing Issues with creating Custom Security Events towards NVM (nvzflows) In my SNA platform.&lt;BR /&gt;Been creating a test Custom Security Event, just to see If it triggers.&lt;BR /&gt;&lt;BR /&gt;"CSE: Forbidden Application"&lt;BR /&gt;When any subject host; using the process "well known .exe" communicates with any peer host, an alarm is raised.&lt;BR /&gt;&lt;BR /&gt;Subject Process Names "well known .exe" on windows hosts.&lt;BR /&gt;&lt;BR /&gt;Saved the Custom Event.&lt;BR /&gt;&lt;BR /&gt;On my endpoint this well known .exe Process Names" triggeres. And It's visibile under the "Report Builder" --&amp;gt;&amp;nbsp;Endpoint Traffic (NVM).&lt;BR /&gt;&lt;BR /&gt;But no alert shows up under my Security Insight Dashbard.&lt;BR /&gt;Why?&lt;BR /&gt;&lt;BR /&gt;The goal of my NVM (nvzflows) Is to create "Custom Security Events" for alerts.&lt;BR /&gt;&lt;BR /&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 05 Feb 2025 10:22:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/security-analytics/cisco-secure-network-analytics-custom-events-not-working-towards/m-p/5257076#M1146</guid>
      <dc:creator>aleksta9826435</dc:creator>
      <dc:date>2025-02-05T10:22:51Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Secure Network Analytics - Custom Events not working towards</title>
      <link>https://community.cisco.com/t5/security-analytics/cisco-secure-network-analytics-custom-events-not-working-towards/m-p/5257128#M1147</link>
      <description>&lt;P&gt;Please can you confirm which version of SNA you have installed?&lt;/P&gt;</description>
      <pubDate>Wed, 05 Feb 2025 13:29:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/security-analytics/cisco-secure-network-analytics-custom-events-not-working-towards/m-p/5257128#M1147</guid>
      <dc:creator>David Salter</dc:creator>
      <dc:date>2025-02-05T13:29:53Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Secure Network Analytics - Custom Events not working towards</title>
      <link>https://community.cisco.com/t5/security-analytics/cisco-secure-network-analytics-custom-events-not-working-towards/m-p/5257138#M1148</link>
      <description>&lt;P&gt;I'm running the latest version.&lt;BR /&gt;7.5.1&lt;/P&gt;</description>
      <pubDate>Wed, 05 Feb 2025 13:44:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/security-analytics/cisco-secure-network-analytics-custom-events-not-working-towards/m-p/5257138#M1148</guid>
      <dc:creator>aleksta9826435</dc:creator>
      <dc:date>2025-02-05T13:44:59Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Secure Network Analytics - Custom Events not working towards</title>
      <link>https://community.cisco.com/t5/security-analytics/cisco-secure-network-analytics-custom-events-not-working-towards/m-p/5257487#M1149</link>
      <description>&lt;P&gt;Unfortunately you cannot use NMV telemetry to trigger a custom security event the way you describe.&amp;nbsp; &lt;BR /&gt;&lt;BR /&gt;The 'worst case scenario' for a host running Secure Client is the remote worker use case where the NVM telemetry may be cached for some time before the user connects back to the corporate network via VPN, at which point the cached telemetry is forwarded to SNA and written to the database however the timestamps will be outside of the 5 minute window used by the core engine for real time detections.&amp;nbsp; Today, NVM can be classed as additional context so it will be visible via Report Builder.&lt;/P&gt;</description>
      <pubDate>Thu, 06 Feb 2025 11:23:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/security-analytics/cisco-secure-network-analytics-custom-events-not-working-towards/m-p/5257487#M1149</guid>
      <dc:creator>David Salter</dc:creator>
      <dc:date>2025-02-06T11:23:02Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Secure Network Analytics - Custom Events not working towards</title>
      <link>https://community.cisco.com/t5/security-analytics/cisco-secure-network-analytics-custom-events-not-working-towards/m-p/5257527#M1150</link>
      <description>&lt;P&gt;Okey. So what you are saying Is that It's not possible to create "Custom Security Events" towards NVM telemetry data?&lt;BR /&gt;My NVM-module configuration Is only for endpoints that are on a "trusted network".&lt;BR /&gt;&lt;BR /&gt;I actually got some hits today in my "Security Insight Dashboard" of yesterdays creation of my Custom Security Event.&lt;BR /&gt;But the alerts Is triggered on others endpoints that not even have the NVM-module installed which Is weird.&lt;BR /&gt;&lt;BR /&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 06 Feb 2025 12:43:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/security-analytics/cisco-secure-network-analytics-custom-events-not-working-towards/m-p/5257527#M1150</guid>
      <dc:creator>aleksta9826435</dc:creator>
      <dc:date>2025-02-06T12:43:25Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Secure Network Analytics - Custom Events not working towards</title>
      <link>https://community.cisco.com/t5/security-analytics/cisco-secure-network-analytics-custom-events-not-working-towards/m-p/5257583#M1151</link>
      <description>&lt;P&gt;Can you share the custom security event configuration?&lt;/P&gt;</description>
      <pubDate>Thu, 06 Feb 2025 14:52:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/security-analytics/cisco-secure-network-analytics-custom-events-not-working-towards/m-p/5257583#M1151</guid>
      <dc:creator>David Salter</dc:creator>
      <dc:date>2025-02-06T14:52:35Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Secure Network Analytics - Custom Events not working towards</title>
      <link>https://community.cisco.com/t5/security-analytics/cisco-secure-network-analytics-custom-events-not-working-towards/m-p/5257672#M1152</link>
      <description>&lt;P&gt;I'll attach the screenshot below.&lt;/P&gt;</description>
      <pubDate>Thu, 06 Feb 2025 16:30:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/security-analytics/cisco-secure-network-analytics-custom-events-not-working-towards/m-p/5257672#M1152</guid>
      <dc:creator>aleksta9826435</dc:creator>
      <dc:date>2025-02-06T16:30:03Z</dc:date>
    </item>
  </channel>
</rss>

