<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco Secure Network Analytics - .CSE Rule Exclude Payload informa in Security Analytics</title>
    <link>https://community.cisco.com/t5/security-analytics/cisco-secure-network-analytics-cse-rule-exclude-payload/m-p/5306604#M1198</link>
    <description>&lt;P&gt;&lt;SPAN class=""&gt;It looks like you're hitting a limitation in Cisco Secure Network Analytics (StealthWatch/SAN)—&lt;STRONG&gt;custom security events (CSEs) don’t support filtering or excluding based on “Subject Payload”&lt;/STRONG&gt;. That filter is only available in &lt;STRONG&gt;Flow Search&lt;/STRONG&gt;, under &lt;EM&gt;Advanced Connection Options → Payload&lt;/EM&gt;, but that same capability isn’t exposed in CSE creation under &lt;EM&gt;Policy Management&lt;/EM&gt;.&lt;/SPAN&gt;&lt;/P&gt;&lt;HR /&gt;&lt;H3&gt;&lt;span class="lia-unicode-emoji" title=":magnifying_glass_tilted_left:"&gt;🔍&lt;/span&gt; What You &lt;EM&gt;Can&lt;/EM&gt; Do Instead&lt;/H3&gt;&lt;H4&gt;1. &lt;STRONG&gt;Pre-filter with Flow Search + Scripted Alerting&lt;/STRONG&gt;&lt;/H4&gt;&lt;UL&gt;&lt;LI&gt;&lt;P&gt;&lt;SPAN class=""&gt;&lt;STRONG&gt;Regularly run&lt;/STRONG&gt; a scheduled Flow Search via API or CLI that includes Payload filters to &lt;STRONG&gt;exclude unwanted “Subject Payload”&lt;/STRONG&gt; values.&lt;/SPAN&gt;&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;&lt;SPAN class=""&gt;&lt;STRONG&gt;Script processing&lt;/STRONG&gt; of the results and generate alerts or write logs externally.&lt;/SPAN&gt;&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;&lt;SPAN class=""&gt;While this doesn’t use CSE, it allows fine-grained payload control.&lt;/SPAN&gt;&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;H4&gt;2. &lt;STRONG&gt;Use Caller Context (Custom Fields)&lt;/STRONG&gt;&lt;/H4&gt;&lt;UL&gt;&lt;LI&gt;&lt;P&gt;&lt;SPAN class=""&gt;In Flow Search, add payload filters to &lt;STRONG&gt;capture only desired events&lt;/STRONG&gt;.&lt;/SPAN&gt;&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;&lt;SPAN class=""&gt;Export these events, then ingest them into your SIEM or Splunk, where you can &lt;STRONG&gt;alert or alert-categorize&lt;/STRONG&gt; based on payload content.&lt;/SPAN&gt;&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;H4&gt;3. &lt;STRONG&gt;File a Feature Request&lt;/STRONG&gt;&lt;/H4&gt;&lt;UL&gt;&lt;LI&gt;&lt;P&gt;&lt;SPAN class=""&gt;Cisco docs and the community confirm this isn’t currently supported&lt;/SPAN&gt; .&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Consider submitting a feature request or POC to Cisco via TAC, asking to add payload filtering into CSE criteria.&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;HR /&gt;&lt;H3&gt;&lt;span class="lia-unicode-emoji" title=":warning:"&gt;⚠️&lt;/span&gt; TL;DR&lt;/H3&gt;&lt;UL&gt;&lt;LI&gt;&lt;P&gt;&lt;STRONG&gt;CSEs&lt;/STRONG&gt;: can filter by host groups, bytes, packets, app, etc., but &lt;STRONG&gt;not by payload fields&lt;/STRONG&gt;.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;&lt;STRONG&gt;Flow Search&lt;/STRONG&gt;: &lt;EM&gt;is&lt;/EM&gt; payload-aware, but results aren’t alerting via CSE.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;&lt;STRONG&gt;Workaround&lt;/STRONG&gt;: Use scheduled Flow Search + scripting (or SIEM ingestion) to replicate what you want.&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;</description>
    <pubDate>Mon, 07 Jul 2025 16:39:51 GMT</pubDate>
    <dc:creator>wajidhassan</dc:creator>
    <dc:date>2025-07-07T16:39:51Z</dc:date>
    <item>
      <title>Cisco Secure Network Analytics - .CSE Rule Exclude Payload information</title>
      <link>https://community.cisco.com/t5/security-analytics/cisco-secure-network-analytics-cse-rule-exclude-payload/m-p/5277384#M1172</link>
      <description>&lt;P&gt;Hi everyone,&lt;/P&gt;&lt;P&gt;Having some .CSE rules when high amount of data Is leaving a internal network. Having alot of false positives related to this.&amp;nbsp;&lt;BR /&gt;And I'm wondering If It's possible in some way to exclude a specifik "Subject Payload" field?&lt;/P&gt;&lt;P&gt;That "Subject Payload" Is visibile due to my SAL logging that I have.&amp;nbsp;&lt;/P&gt;&lt;P&gt;From a regular "flow search" I can exclude&amp;nbsp; the "Subject Payload" field under,&amp;nbsp;&lt;BR /&gt;--&amp;gt; Advanced Connection Options&lt;BR /&gt;--&amp;gt; Payload&lt;/P&gt;&lt;P&gt;But this Is not available under,&lt;BR /&gt;--&amp;gt; Policy Management&lt;BR /&gt;--&amp;gt; Custome Security Events&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 02 Apr 2025 07:09:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/security-analytics/cisco-secure-network-analytics-cse-rule-exclude-payload/m-p/5277384#M1172</guid>
      <dc:creator>aleksta9826435</dc:creator>
      <dc:date>2025-04-02T07:09:22Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Secure Network Analytics - .CSE Rule Exclude Payload informa</title>
      <link>https://community.cisco.com/t5/security-analytics/cisco-secure-network-analytics-cse-rule-exclude-payload/m-p/5306604#M1198</link>
      <description>&lt;P&gt;&lt;SPAN class=""&gt;It looks like you're hitting a limitation in Cisco Secure Network Analytics (StealthWatch/SAN)—&lt;STRONG&gt;custom security events (CSEs) don’t support filtering or excluding based on “Subject Payload”&lt;/STRONG&gt;. That filter is only available in &lt;STRONG&gt;Flow Search&lt;/STRONG&gt;, under &lt;EM&gt;Advanced Connection Options → Payload&lt;/EM&gt;, but that same capability isn’t exposed in CSE creation under &lt;EM&gt;Policy Management&lt;/EM&gt;.&lt;/SPAN&gt;&lt;/P&gt;&lt;HR /&gt;&lt;H3&gt;&lt;span class="lia-unicode-emoji" title=":magnifying_glass_tilted_left:"&gt;🔍&lt;/span&gt; What You &lt;EM&gt;Can&lt;/EM&gt; Do Instead&lt;/H3&gt;&lt;H4&gt;1. &lt;STRONG&gt;Pre-filter with Flow Search + Scripted Alerting&lt;/STRONG&gt;&lt;/H4&gt;&lt;UL&gt;&lt;LI&gt;&lt;P&gt;&lt;SPAN class=""&gt;&lt;STRONG&gt;Regularly run&lt;/STRONG&gt; a scheduled Flow Search via API or CLI that includes Payload filters to &lt;STRONG&gt;exclude unwanted “Subject Payload”&lt;/STRONG&gt; values.&lt;/SPAN&gt;&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;&lt;SPAN class=""&gt;&lt;STRONG&gt;Script processing&lt;/STRONG&gt; of the results and generate alerts or write logs externally.&lt;/SPAN&gt;&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;&lt;SPAN class=""&gt;While this doesn’t use CSE, it allows fine-grained payload control.&lt;/SPAN&gt;&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;H4&gt;2. &lt;STRONG&gt;Use Caller Context (Custom Fields)&lt;/STRONG&gt;&lt;/H4&gt;&lt;UL&gt;&lt;LI&gt;&lt;P&gt;&lt;SPAN class=""&gt;In Flow Search, add payload filters to &lt;STRONG&gt;capture only desired events&lt;/STRONG&gt;.&lt;/SPAN&gt;&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;&lt;SPAN class=""&gt;Export these events, then ingest them into your SIEM or Splunk, where you can &lt;STRONG&gt;alert or alert-categorize&lt;/STRONG&gt; based on payload content.&lt;/SPAN&gt;&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;H4&gt;3. &lt;STRONG&gt;File a Feature Request&lt;/STRONG&gt;&lt;/H4&gt;&lt;UL&gt;&lt;LI&gt;&lt;P&gt;&lt;SPAN class=""&gt;Cisco docs and the community confirm this isn’t currently supported&lt;/SPAN&gt; .&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Consider submitting a feature request or POC to Cisco via TAC, asking to add payload filtering into CSE criteria.&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;HR /&gt;&lt;H3&gt;&lt;span class="lia-unicode-emoji" title=":warning:"&gt;⚠️&lt;/span&gt; TL;DR&lt;/H3&gt;&lt;UL&gt;&lt;LI&gt;&lt;P&gt;&lt;STRONG&gt;CSEs&lt;/STRONG&gt;: can filter by host groups, bytes, packets, app, etc., but &lt;STRONG&gt;not by payload fields&lt;/STRONG&gt;.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;&lt;STRONG&gt;Flow Search&lt;/STRONG&gt;: &lt;EM&gt;is&lt;/EM&gt; payload-aware, but results aren’t alerting via CSE.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;&lt;STRONG&gt;Workaround&lt;/STRONG&gt;: Use scheduled Flow Search + scripting (or SIEM ingestion) to replicate what you want.&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;</description>
      <pubDate>Mon, 07 Jul 2025 16:39:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/security-analytics/cisco-secure-network-analytics-cse-rule-exclude-payload/m-p/5306604#M1198</guid>
      <dc:creator>wajidhassan</dc:creator>
      <dc:date>2025-07-07T16:39:51Z</dc:date>
    </item>
  </channel>
</rss>

