<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Create Alert base on Host and Peer comminucation in Security Analytics</title>
    <link>https://community.cisco.com/t5/security-analytics/create-alert-base-on-host-and-peer-comminucation/m-p/4273989#M620</link>
    <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have 2 devices and I would like to create an alert on Stealthwatch when there is another communication except between those 2 devices.&lt;/P&gt;&lt;P&gt;let say device A and Device B should communicate&lt;/P&gt;&lt;P&gt;and if Device A tries to communicate with Device C I would like to get an alert.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;does anyone know how to create such an alert in Stealthwatch?&lt;/P&gt;</description>
    <pubDate>Sun, 17 Jan 2021 12:09:08 GMT</pubDate>
    <dc:creator>DmitryVolk83628</dc:creator>
    <dc:date>2021-01-17T12:09:08Z</dc:date>
    <item>
      <title>Create Alert base on Host and Peer comminucation</title>
      <link>https://community.cisco.com/t5/security-analytics/create-alert-base-on-host-and-peer-comminucation/m-p/4273989#M620</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have 2 devices and I would like to create an alert on Stealthwatch when there is another communication except between those 2 devices.&lt;/P&gt;&lt;P&gt;let say device A and Device B should communicate&lt;/P&gt;&lt;P&gt;and if Device A tries to communicate with Device C I would like to get an alert.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;does anyone know how to create such an alert in Stealthwatch?&lt;/P&gt;</description>
      <pubDate>Sun, 17 Jan 2021 12:09:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/security-analytics/create-alert-base-on-host-and-peer-comminucation/m-p/4273989#M620</guid>
      <dc:creator>DmitryVolk83628</dc:creator>
      <dc:date>2021-01-17T12:09:08Z</dc:date>
    </item>
    <item>
      <title>Re: Create Alert base on Host and Peer comminucation</title>
      <link>https://community.cisco.com/t5/security-analytics/create-alert-base-on-host-and-peer-comminucation/m-p/4274578#M622</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;you can use either the relationship policies or the custom security events to track segmentation violation based on the specific use case you have. Please look at the Stealthwatch use cases if you want a list of examples.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this helps.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Dario&lt;/P&gt;</description>
      <pubDate>Mon, 18 Jan 2021 14:12:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/security-analytics/create-alert-base-on-host-and-peer-comminucation/m-p/4274578#M622</guid>
      <dc:creator>dcavalla</dc:creator>
      <dc:date>2021-01-18T14:12:28Z</dc:date>
    </item>
    <item>
      <title>Re: Create Alert base on Host and Peer comminucation</title>
      <link>https://community.cisco.com/t5/security-analytics/create-alert-base-on-host-and-peer-comminucation/m-p/4275002#M623</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In version 7.3.0, in the SMC GUI go to Configure / Policy Management, and then select at the top right&amp;nbsp; Create New Policy / Custom Security Event&lt;/P&gt;&lt;P&gt;Give it a Name, and optionally provide a Description.&lt;/P&gt;&lt;P&gt;Change the Status to ON&lt;/P&gt;&lt;P&gt;Click the plus sign +&lt;/P&gt;&lt;P&gt;Select from the dropdown list:&amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;/P&gt;&lt;P&gt;NOTES:&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp;1) Items in the dropdown list described as "Subject" are the SOURCE items, and the ones described as "Peer" are the DESTINATION items,&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; 2) An item can be either a Host Group, a Host, or even Users, Devices, etc&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; 3) You can add one or more items as Subject or Peer.&lt;/P&gt;&lt;P&gt;STRATEGY: Create a Host Group "HGroup01" that includes device A AND device B, or you can reference the devices by separately. And then add into the Subject Host Group items like "Inside Hosts", "Outside Hosts", and any other Host Group you want to alarm that communicates with PEER "HGroup01" or the device A or device B referenced separately.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;At the end if device A and B are referenced separately the Policy should read something similar :&amp;nbsp; "When any subject host group communicates with device A or device B, an alarm is raised"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You may consider creating another Policy where the Subjects are the devices A and B, and the Peers are the&amp;nbsp;"Inside Hosts" and "Outside Hosts"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 19 Jan 2021 04:23:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/security-analytics/create-alert-base-on-host-and-peer-comminucation/m-p/4275002#M623</guid>
      <dc:creator>juanpablorivera</dc:creator>
      <dc:date>2021-01-19T04:23:17Z</dc:date>
    </item>
  </channel>
</rss>

