<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Stealthwatch Capacity planning in Security Analytics</title>
    <link>https://community.cisco.com/t5/security-analytics/stealthwatch-capacity-planning/m-p/3460706#M71</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;thank you for reply, i think i misunderstand the topic of this thread &lt;IMG src="https://community.cisco.com/legacyfs/online/emoticons/laugh.png" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 21 Mar 2018 00:58:01 GMT</pubDate>
    <dc:creator>lin jia</dc:creator>
    <dc:date>2018-03-21T00:58:01Z</dc:date>
    <item>
      <title>Stealthwatch Capacity planning</title>
      <link>https://community.cisco.com/t5/security-analytics/stealthwatch-capacity-planning/m-p/3460702#M67</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What are the parameters other than CPU, Memory and Storage that should be monitored on Stealthwatch in order to do capacity planning effectively. Following are been deployed int the production environment &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Calibri',sans-serif; color: black;"&gt;FlowCollector for NetFlow 4000&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: black; font-size: 11.0pt; font-family: 'Calibri',sans-serif;"&gt;FlowReplicator 2000 - UDP Director&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: black; font-size: 11.0pt; font-family: 'Calibri',sans-serif;"&gt;SMC- VM&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: black; font-size: 11.0pt; font-family: 'Calibri',sans-serif;"&gt;FlowSensor 1000&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 29 May 2017 08:34:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/security-analytics/stealthwatch-capacity-planning/m-p/3460702#M67</guid>
      <dc:creator>kmittal</dc:creator>
      <dc:date>2017-05-29T08:34:12Z</dc:date>
    </item>
    <item>
      <title>Re: Stealthwatch Capacity planning</title>
      <link>https://community.cisco.com/t5/security-analytics/stealthwatch-capacity-planning/m-p/3460703#M68</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Great question, @&lt;SPAN class="j-post-author"&gt;&lt;STRONG&gt;&lt;A href="https://community.cisco.com//people/kmittal"&gt;kmittal&lt;/A&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;At the heart of the system the FlowCollector 4000 is rated to consume a 120,000 flows/sec consistently.&amp;nbsp; You can see that consumption on the Flow Collector Dashboard in the Desktop Client.&amp;nbsp; You already mentioned storage but look at the appliance interface on the FlowCollector under the Database Statistics view you will see how much is being utilized and how many days of retention you have.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The UDP Director appliance UI will show you the pps in/out and you'll want to be mindful of, the link utilization of the production interface because that's generally the first bottleneck folks encounter on that device.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On the FlowSensor, monitor the link utilization.&amp;nbsp; You can use the Interface Status view of that exporter. You don't want to overrun the bandwidth of the input link or you'll miss traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On the SMC you'll have some slowness if you're letting the whole SOC and NOC teams bang on it while running heavy reports and managing two dozen FlowCollectors during peak traffic times.&amp;nbsp; Fortunately, the stuff you need to monitor there is already in the Desktop Client, just double-click on the SMC in the enterprise tree on the left.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--jg&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 Jun 2017 15:08:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/security-analytics/stealthwatch-capacity-planning/m-p/3460703#M68</guid>
      <dc:creator>jamegill</dc:creator>
      <dc:date>2017-06-22T15:08:10Z</dc:date>
    </item>
    <item>
      <title>Re: Stealthwatch Capacity planning</title>
      <link>https://community.cisco.com/t5/security-analytics/stealthwatch-capacity-planning/m-p/3460704#M69</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi, James Gill， &lt;/P&gt;&lt;P&gt;&lt;SPAN lang="en"&gt;I would like to know if there is a specific case for capacity planning, such as whether it can provide recommendations for purchasing more products by observing network traffic trends and network load trends. &lt;SPAN&gt;However, I have a question. The network capacity is often related to the number of terminals. The number of terminals is often influenced by human factors. Can we predict the number of terminals?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 19 Mar 2018 07:12:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/security-analytics/stealthwatch-capacity-planning/m-p/3460704#M69</guid>
      <dc:creator>lin jia</dc:creator>
      <dc:date>2018-03-19T07:12:14Z</dc:date>
    </item>
    <item>
      <title>Re: Stealthwatch Capacity planning</title>
      <link>https://community.cisco.com/t5/security-analytics/stealthwatch-capacity-planning/m-p/3460705#M70</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello, lin jia.&lt;/P&gt;&lt;P&gt;The original question asked about planning for resources needed to support the Stealthwatch system.&amp;nbsp; Here, you appear to be asking about network capacity planning more generally.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Within Stealthwatch you can observe trends and set thresholds to get alarms when monitored network interface utilization surpasses a given percentage (default is 80%).&amp;nbsp;&amp;nbsp; Stealthwatch is a great tool for visibility generally and can provide a wealth of information to assist.&amp;nbsp; However it is not designed as a capacity planning tool and does not build in the usual assumptions used by specialists in that area.&amp;nbsp;&amp;nbsp; Rather, Stealthwatch includes specialized algorithms to detect security anomalies and highlight behavior patterns relevant to securito operations and incident response.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope that helps!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--jg&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 20 Mar 2018 17:02:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/security-analytics/stealthwatch-capacity-planning/m-p/3460705#M70</guid>
      <dc:creator>jamegill</dc:creator>
      <dc:date>2018-03-20T17:02:23Z</dc:date>
    </item>
    <item>
      <title>Re: Stealthwatch Capacity planning</title>
      <link>https://community.cisco.com/t5/security-analytics/stealthwatch-capacity-planning/m-p/3460706#M71</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;thank you for reply, i think i misunderstand the topic of this thread &lt;IMG src="https://community.cisco.com/legacyfs/online/emoticons/laugh.png" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 21 Mar 2018 00:58:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/security-analytics/stealthwatch-capacity-planning/m-p/3460706#M71</guid>
      <dc:creator>lin jia</dc:creator>
      <dc:date>2018-03-21T00:58:01Z</dc:date>
    </item>
  </channel>
</rss>

