<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Stealthwatch full netflow analytics in Security Analytics</title>
    <link>https://community.cisco.com/t5/security-analytics/stealthwatch-full-netflow-analytics/m-p/4096020#M525</link>
    <description>&lt;P&gt;1. Yes, Stealthwatch can marge&amp;nbsp;&lt;SPAN&gt;the pre/post NAT flows. And all information is shown in the GUI.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;2. The timing of FlowData that is coming from FlowDevice(Router, Switch, FW) is up to Device side configuration. Please check Device side Flow export timing.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 02 Jun 2020 08:41:23 GMT</pubDate>
    <dc:creator>kyoshiik</dc:creator>
    <dc:date>2020-06-02T08:41:23Z</dc:date>
    <item>
      <title>Stealthwatch full netflow analytics</title>
      <link>https://community.cisco.com/t5/security-analytics/stealthwatch-full-netflow-analytics/m-p/4095965#M524</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am new to Stealthwatch and have some questions which I cannot find in the other discussions in the community forum.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have a small deployment at one of our customers with 1 SMC and 1 FC. It is a multi-vendor environment. We have cisco, palo alto, fortinet which all seem to support netflow v9 or ipfix.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;From the documentation I could not quite understand how the flow-stitching (into single flow session in the GUI) and NAT stitching is done.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1. When we have device doing NAT translation and exporting full netflow, NAT stitching is supposed to see this as per the documentation. But will the pre/post NAT flows be merged? Am I supposed to see my session flow with the internal client address only and the respective destination server? Where is the NAT IP shown in the web GUI?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2. When I make a simple file transfer test to an external server I see the flow from the search appearing. Client -&amp;gt; Server session with internal IP to the external server IP. However the data that has been transffered is 2-3 times more i.e. instead of 50Mb it is showing 148Mb. Is this a limitation of the flow collector doing the flow stitching or we might have some wrong configuration.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I will highly appreciate any advice.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Emil&lt;/P&gt;</description>
      <pubDate>Tue, 02 Jun 2020 07:08:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/security-analytics/stealthwatch-full-netflow-analytics/m-p/4095965#M524</guid>
      <dc:creator>efellows.support</dc:creator>
      <dc:date>2020-06-02T07:08:19Z</dc:date>
    </item>
    <item>
      <title>Re: Stealthwatch full netflow analytics</title>
      <link>https://community.cisco.com/t5/security-analytics/stealthwatch-full-netflow-analytics/m-p/4096020#M525</link>
      <description>&lt;P&gt;1. Yes, Stealthwatch can marge&amp;nbsp;&lt;SPAN&gt;the pre/post NAT flows. And all information is shown in the GUI.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;2. The timing of FlowData that is coming from FlowDevice(Router, Switch, FW) is up to Device side configuration. Please check Device side Flow export timing.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 02 Jun 2020 08:41:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/security-analytics/stealthwatch-full-netflow-analytics/m-p/4096020#M525</guid>
      <dc:creator>kyoshiik</dc:creator>
      <dc:date>2020-06-02T08:41:23Z</dc:date>
    </item>
    <item>
      <title>Re: Stealthwatch full netflow analytics</title>
      <link>https://community.cisco.com/t5/security-analytics/stealthwatch-full-netflow-analytics/m-p/4096067#M527</link>
      <description>&lt;P&gt;Hello Emil,&lt;/P&gt;
&lt;P&gt;Stealthwatch is capable of ingesting NAT info from IPFIX NAT and NSEL. That will allow Steathwatch to stitch flows together and this process is quite reliable.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;NAT IP is shown when you run a flow search and enable the relative translated host column.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For the file transfer issue, I would open a TAC case. Our Stealthwatch specialists team are located in US, EMEAR and APJC. They are typically very responsive.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this helps.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Dario&lt;/P&gt;</description>
      <pubDate>Tue, 02 Jun 2020 10:54:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/security-analytics/stealthwatch-full-netflow-analytics/m-p/4096067#M527</guid>
      <dc:creator>dcavalla</dc:creator>
      <dc:date>2020-06-02T10:54:51Z</dc:date>
    </item>
  </channel>
</rss>

