<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic StealthWatch host group baseline in Security Analytics</title>
    <link>https://community.cisco.com/t5/security-analytics/stealthwatch-host-group-baseline/m-p/4288272#M629</link>
    <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a question about host group configurations and conflicting baseline configuration.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If I understand correctly the 'Enable baselining for Hosts in this Group' controls if hosts are baselined individually or if a baseline is taken for the whole host group. It makes sense to disable this for a host group that uses dynamic IP addresses&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In the following example, what would be applied, individual baselining or host group baselining:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;a host sits in 2 groups with different policies:&lt;OL&gt;&lt;LI&gt;'by location' &amp;gt; 'my campus': enable baselining turned on&lt;/LI&gt;&lt;LI&gt;'by function' &amp;gt; 'DHCP clients': enable baselining turned off&lt;/LI&gt;&lt;/OL&gt;&lt;/LI&gt;&lt;LI&gt;host group hierarchy&lt;OL&gt;&lt;LI&gt;'peripherals' (On) &amp;gt; 'printers (Off): What would be applied for hosts in the printers host group, is there any inheritance for this setting?&lt;/LI&gt;&lt;/OL&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
    <pubDate>Mon, 08 Feb 2021 19:54:56 GMT</pubDate>
    <dc:creator>Bart G</dc:creator>
    <dc:date>2021-02-08T19:54:56Z</dc:date>
    <item>
      <title>StealthWatch host group baseline</title>
      <link>https://community.cisco.com/t5/security-analytics/stealthwatch-host-group-baseline/m-p/4288272#M629</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a question about host group configurations and conflicting baseline configuration.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If I understand correctly the 'Enable baselining for Hosts in this Group' controls if hosts are baselined individually or if a baseline is taken for the whole host group. It makes sense to disable this for a host group that uses dynamic IP addresses&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In the following example, what would be applied, individual baselining or host group baselining:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;a host sits in 2 groups with different policies:&lt;OL&gt;&lt;LI&gt;'by location' &amp;gt; 'my campus': enable baselining turned on&lt;/LI&gt;&lt;LI&gt;'by function' &amp;gt; 'DHCP clients': enable baselining turned off&lt;/LI&gt;&lt;/OL&gt;&lt;/LI&gt;&lt;LI&gt;host group hierarchy&lt;OL&gt;&lt;LI&gt;'peripherals' (On) &amp;gt; 'printers (Off): What would be applied for hosts in the printers host group, is there any inheritance for this setting?&lt;/LI&gt;&lt;/OL&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Mon, 08 Feb 2021 19:54:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/security-analytics/stealthwatch-host-group-baseline/m-p/4288272#M629</guid>
      <dc:creator>Bart G</dc:creator>
      <dc:date>2021-02-08T19:54:56Z</dc:date>
    </item>
    <item>
      <title>Re: StealthWatch host group baseline</title>
      <link>https://community.cisco.com/t5/security-analytics/stealthwatch-host-group-baseline/m-p/4288307#M631</link>
      <description>&lt;P&gt;By default, every individual host is baselined within the "Inside Hosts" host group. Stealthwatch baselines only aggregate host behavior at the host group level for the "Outside Hosts" host group.&lt;/P&gt;&lt;P&gt;If you turn off "Enable baselining for Hosts in this Group", Stealthwatch will baseline the aggregate host behavior at the host group level.&lt;/P&gt;&lt;P&gt;I have not been able to find any documentation to back this part up but I believe if your host is a member of two different host groups who are not children or parents of each other and one of them has the default enabled setting of "Enable baselining for Hosts in this Group", that host will be individually baselined. If the host is a member of a child host group who has disabled that option, the host will not be individually baselined.&lt;/P&gt;</description>
      <pubDate>Mon, 08 Feb 2021 21:03:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/security-analytics/stealthwatch-host-group-baseline/m-p/4288307#M631</guid>
      <dc:creator>TJ-20933766</dc:creator>
      <dc:date>2021-02-08T21:03:34Z</dc:date>
    </item>
  </channel>
</rss>

