<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: NVM Telemetry – Flow to Process Correlation in Security Analytics</title>
    <link>https://community.cisco.com/t5/security-analytics/nvm-telemetry-flow-to-process-correlation/m-p/5328020#M1241</link>
    <description>&lt;P&gt;The advanced Subject / Peer Options includes the ability to filter for both &lt;STRONG&gt;Process Name&lt;/STRONG&gt; and &lt;STRONG&gt;File Hash&lt;/STRONG&gt; associated with the flow.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="DavidSalter_0-1757318231662.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/251535i01965D06F0798005/image-size/medium?v=v2&amp;amp;px=400" role="button" title="DavidSalter_0-1757318231662.png" alt="DavidSalter_0-1757318231662.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;To get visibility in the Flow Table, use&amp;nbsp;&lt;STRONG&gt;Manage Columns&lt;/STRONG&gt; to add the required fields, for example:&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="DavidSalter_1-1757318410030.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/251536iF645235F7665FE0D/image-size/medium?v=v2&amp;amp;px=400" role="button" title="DavidSalter_1-1757318410030.png" alt="DavidSalter_1-1757318410030.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 08 Sep 2025 08:00:27 GMT</pubDate>
    <dc:creator>David Salter</dc:creator>
    <dc:date>2025-09-08T08:00:27Z</dc:date>
    <item>
      <title>NVM Telemetry – Flow to Process Correlation</title>
      <link>https://community.cisco.com/t5/security-analytics/nvm-telemetry-flow-to-process-correlation/m-p/5327888#M1240</link>
      <description>&lt;P&gt;Hello Community,&lt;/P&gt;
&lt;P&gt;In a scenario where NVM telemetry is enabled from user endpoint, is it possible to directly correlate a network flow with the associated user endpoint process name and process ID from the SNA console (7.5.2)?&lt;/P&gt;
&lt;P&gt;If not, is there any manual method or workaround to achieve this correlation between flow data and process details?&lt;/P&gt;
&lt;P&gt;Appreciate any insights, best practices, or tools that could help with this mapping.&lt;/P&gt;
&lt;P&gt;I really appreciate any help you can provide.&lt;/P&gt;</description>
      <pubDate>Sun, 07 Sep 2025 06:35:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/security-analytics/nvm-telemetry-flow-to-process-correlation/m-p/5327888#M1240</guid>
      <dc:creator>jitendrac</dc:creator>
      <dc:date>2025-09-07T06:35:01Z</dc:date>
    </item>
    <item>
      <title>Re: NVM Telemetry – Flow to Process Correlation</title>
      <link>https://community.cisco.com/t5/security-analytics/nvm-telemetry-flow-to-process-correlation/m-p/5328020#M1241</link>
      <description>&lt;P&gt;The advanced Subject / Peer Options includes the ability to filter for both &lt;STRONG&gt;Process Name&lt;/STRONG&gt; and &lt;STRONG&gt;File Hash&lt;/STRONG&gt; associated with the flow.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="DavidSalter_0-1757318231662.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/251535i01965D06F0798005/image-size/medium?v=v2&amp;amp;px=400" role="button" title="DavidSalter_0-1757318231662.png" alt="DavidSalter_0-1757318231662.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;To get visibility in the Flow Table, use&amp;nbsp;&lt;STRONG&gt;Manage Columns&lt;/STRONG&gt; to add the required fields, for example:&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="DavidSalter_1-1757318410030.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/251536iF645235F7665FE0D/image-size/medium?v=v2&amp;amp;px=400" role="button" title="DavidSalter_1-1757318410030.png" alt="DavidSalter_1-1757318410030.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 08 Sep 2025 08:00:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/security-analytics/nvm-telemetry-flow-to-process-correlation/m-p/5328020#M1241</guid>
      <dc:creator>David Salter</dc:creator>
      <dc:date>2025-09-08T08:00:27Z</dc:date>
    </item>
    <item>
      <title>Re: NVM Telemetry – Flow to Process Correlation</title>
      <link>https://community.cisco.com/t5/security-analytics/nvm-telemetry-flow-to-process-correlation/m-p/5330429#M1249</link>
      <description>&lt;P&gt;Hi David,&lt;BR /&gt;Great to see you here after such a long time!&lt;BR data-start="224" data-end="227" /&gt;Thanks for the detailed pointers.&amp;nbsp;Thanks for sharing your expertise here.&lt;BR /&gt;Your pointers help, but my goal is to &lt;STRONG data-start="702" data-end="714"&gt;automate&lt;/STRONG&gt; the step that will get&amp;nbsp;&lt;STRONG data-start="738" data-end="755"&gt;process names&lt;/STRONG&gt; for flows tied to an alarm.&amp;nbsp;Manual filtering works but doesn’t scale.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 16 Sep 2025 07:19:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/security-analytics/nvm-telemetry-flow-to-process-correlation/m-p/5330429#M1249</guid>
      <dc:creator>jitendrac</dc:creator>
      <dc:date>2025-09-16T07:19:04Z</dc:date>
    </item>
    <item>
      <title>Re: NVM Telemetry – Flow to Process Correlation</title>
      <link>https://community.cisco.com/t5/security-analytics/nvm-telemetry-flow-to-process-correlation/m-p/5330501#M1250</link>
      <description>&lt;P&gt;Thanks! I'm still here, 19 years and counting.&lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;BR /&gt;It is possible to automate the query via the Manager API.&amp;nbsp; The documentation for the nvm-flows API call you need is the&amp;nbsp; under&amp;nbsp;&lt;A href="https://developer.cisco.com/docs/stealthwatch/enterprise/reporting-api-version-1/" target="_blank" rel="noopener"&gt;https://developer.cisco.com/docs/stealthwatch/enterprise/reporting-api-version-1/&lt;/A&gt;.&lt;/P&gt;</description>
      <pubDate>Tue, 16 Sep 2025 10:14:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/security-analytics/nvm-telemetry-flow-to-process-correlation/m-p/5330501#M1250</guid>
      <dc:creator>David Salter</dc:creator>
      <dc:date>2025-09-16T10:14:30Z</dc:date>
    </item>
  </channel>
</rss>

