<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Stealthwatch Flows in Security Analytics</title>
    <link>https://community.cisco.com/t5/security-analytics/stealthwatch-flows/m-p/4731027#M893</link>
    <description>&lt;P&gt;Hi -&lt;/P&gt;
&lt;P&gt;As is usual with IT questions the answer starts with 'It Depends'.&amp;nbsp; For instance if you want to be able to catch traffic that may be moving between 2 devices connected to the same Access Switch, you would of course have to find a way to consume that telemetry...either Netflow or SPAN.&amp;nbsp; However if in your environment intra-switch lateral traffic like that is not allowed then it sounds like your capture at the Distro Switch is sufficient for your environment.&amp;nbsp;&amp;nbsp;&lt;BR /&gt;If you are using the SNA (Stealthwatch Enterprise) product then you do want to be smart about consuming your flow licenses, which it sounds like you are.&amp;nbsp; If you are using SCA (Secure Cloud) licensing is done differently - I couldn't tell because you tagged both in your question.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 01 Dec 2022 15:44:04 GMT</pubDate>
    <dc:creator>rocedar</dc:creator>
    <dc:date>2022-12-01T15:44:04Z</dc:date>
    <item>
      <title>Stealthwatch Flows</title>
      <link>https://community.cisco.com/t5/security-analytics/stealthwatch-flows/m-p/4600465#M785</link>
      <description>&lt;P&gt;does anyone have experience with this or can perhaps guide me on this question&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If i have a Distribution device with 100 Edge device hanging off the Distribution all L3 and i want to enable Netflow to export flows to the collector.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Isn't the distribution the only place that i should configure the exporter to see all this traffic from the edge's&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;what benefit do i get configuring it on all the edge devices and the distribution. I would see the same flow s? Plus i would use up Flow licenses.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Apr 2022 02:46:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/security-analytics/stealthwatch-flows/m-p/4600465#M785</guid>
      <dc:creator>x00008037</dc:creator>
      <dc:date>2022-04-27T02:46:48Z</dc:date>
    </item>
    <item>
      <title>Re: Stealthwatch Flows</title>
      <link>https://community.cisco.com/t5/security-analytics/stealthwatch-flows/m-p/4731027#M893</link>
      <description>&lt;P&gt;Hi -&lt;/P&gt;
&lt;P&gt;As is usual with IT questions the answer starts with 'It Depends'.&amp;nbsp; For instance if you want to be able to catch traffic that may be moving between 2 devices connected to the same Access Switch, you would of course have to find a way to consume that telemetry...either Netflow or SPAN.&amp;nbsp; However if in your environment intra-switch lateral traffic like that is not allowed then it sounds like your capture at the Distro Switch is sufficient for your environment.&amp;nbsp;&amp;nbsp;&lt;BR /&gt;If you are using the SNA (Stealthwatch Enterprise) product then you do want to be smart about consuming your flow licenses, which it sounds like you are.&amp;nbsp; If you are using SCA (Secure Cloud) licensing is done differently - I couldn't tell because you tagged both in your question.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 01 Dec 2022 15:44:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/security-analytics/stealthwatch-flows/m-p/4731027#M893</guid>
      <dc:creator>rocedar</dc:creator>
      <dc:date>2022-12-01T15:44:04Z</dc:date>
    </item>
  </channel>
</rss>

