<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Stealthwatch Mitigation Actions in Security Analytics</title>
    <link>https://community.cisco.com/t5/security-analytics/stealthwatch-mitigation-actions/m-p/3497323#M9</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ah I see, does this mitigation capability still works with ASA? Can't find any documentation with it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And by the way, my FlowSensor can't make use of its DPI capabilities to sense L7 Application. When i set my flow sensor to point to FlowCollector, in SMC, it fell into Exporters category, not Flow Sensor, any help?&lt;IMG alt="Screenshot_1.png" class="image-1 jive-image" src="https://community.cisco.com/legacyfs/online/fusion/105498_Screenshot_1.png" style="height: auto;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 21 Mar 2017 07:19:45 GMT</pubDate>
    <dc:creator>Andryan Viryadi Tanamir</dc:creator>
    <dc:date>2017-03-21T07:19:45Z</dc:date>
    <item>
      <title>Stealthwatch Mitigation Actions</title>
      <link>https://community.cisco.com/t5/security-analytics/stealthwatch-mitigation-actions/m-p/3497321#M7</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I'm experimenting with Stealthwatch with my labs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I currently deployed SMC, FlowCollector and FlowSensor and integrated with Cisco ISE 2.1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For anyone who has deployed Stealtwatch, do Stealthwatch support automatic mitigation for alarms triggered? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have searched and found some ambiguity in documents. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Attached below is the document I found in Stealthwatch help section&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What mitigation device does the documents states? Can Stealthwatch do a automatic mitigation via Cisco ISE?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 06 Mar 2017 07:23:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/security-analytics/stealthwatch-mitigation-actions/m-p/3497321#M7</guid>
      <dc:creator>Andryan Viryadi Tanamir</dc:creator>
      <dc:date>2017-03-06T07:23:22Z</dc:date>
    </item>
    <item>
      <title>Re: Stealthwatch Mitigation Actions</title>
      <link>https://community.cisco.com/t5/security-analytics/stealthwatch-mitigation-actions/m-p/3497322#M8</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Andryan,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The document you are referring to describes a Stealthwatch mitigation capability that was developed to work with the Cisco ASA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Currently Stealthwatch does not offer 'automatic' mitigation via Cisco ISE.&amp;nbsp; The Stealthwatch host 'Quarantine' function requires that a user to submit the request which is processed via pxGrid and assigns the default remediation policy define on the ISE to the selected host.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Brian&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Mar 2017 13:17:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/security-analytics/stealthwatch-mitigation-actions/m-p/3497322#M8</guid>
      <dc:creator>__bford__</dc:creator>
      <dc:date>2017-03-14T13:17:42Z</dc:date>
    </item>
    <item>
      <title>Re: Stealthwatch Mitigation Actions</title>
      <link>https://community.cisco.com/t5/security-analytics/stealthwatch-mitigation-actions/m-p/3497323#M9</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ah I see, does this mitigation capability still works with ASA? Can't find any documentation with it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And by the way, my FlowSensor can't make use of its DPI capabilities to sense L7 Application. When i set my flow sensor to point to FlowCollector, in SMC, it fell into Exporters category, not Flow Sensor, any help?&lt;IMG alt="Screenshot_1.png" class="image-1 jive-image" src="https://community.cisco.com/legacyfs/online/fusion/105498_Screenshot_1.png" style="height: auto;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 21 Mar 2017 07:19:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/security-analytics/stealthwatch-mitigation-actions/m-p/3497323#M9</guid>
      <dc:creator>Andryan Viryadi Tanamir</dc:creator>
      <dc:date>2017-03-21T07:19:45Z</dc:date>
    </item>
    <item>
      <title>Re: Stealthwatch Mitigation Actions</title>
      <link>https://community.cisco.com/t5/security-analytics/stealthwatch-mitigation-actions/m-p/3497324#M10</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Andryan, the remote SSH mitigation into an ASA still functions in the java client.&amp;nbsp; As for the exporter issue, you'll want to double check the Flow Sensor's export settings via it's web interface.&amp;nbsp; It's likely set to export as v9 and not IPFIX.&amp;nbsp; Please ensure it's exporting as IPFIX and that should resolve it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;BR /&gt;Jeff&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 21 Mar 2017 12:25:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/security-analytics/stealthwatch-mitigation-actions/m-p/3497324#M10</guid>
      <dc:creator>jemoncri</dc:creator>
      <dc:date>2017-03-21T12:25:20Z</dc:date>
    </item>
    <item>
      <title>Re: Stealthwatch Mitigation Actions</title>
      <link>https://community.cisco.com/t5/security-analytics/stealthwatch-mitigation-actions/m-p/3497325#M11</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ah thanks ! So much trouble done just for this !! &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Dees that mean I can finally sitting down waiting for the FlowSensor populate the packets received by itself using DPI?&lt;/P&gt;&lt;P&gt;I have deployed it for almost 2 weeks and all I got in Top Applications are Unclassified HTTP and Unclassified HTTPS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To clarify, if I didn't deploy FlowSensor at all in my deployment, does it means I will lost the visibility of applications etc ?&lt;/P&gt;&lt;P&gt;Thanks &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 21 Mar 2017 13:36:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/security-analytics/stealthwatch-mitigation-actions/m-p/3497325#M11</guid>
      <dc:creator>Andryan Viryadi Tanamir</dc:creator>
      <dc:date>2017-03-21T13:36:45Z</dc:date>
    </item>
    <item>
      <title>Re: Stealthwatch Mitigation Actions</title>
      <link>https://community.cisco.com/t5/security-analytics/stealthwatch-mitigation-actions/m-p/3497326#M12</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No problem!  Make sure the SPAN is correctly configured going into the Flow Sensor’s monitor port, otherwise you will not be able to get DPI working properly.  DPI is one method of application verification, the other is via NBAR if you have an exporting device that supports NBAR.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 21 Mar 2017 13:59:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/security-analytics/stealthwatch-mitigation-actions/m-p/3497326#M12</guid>
      <dc:creator>jemoncri</dc:creator>
      <dc:date>2017-03-21T13:59:36Z</dc:date>
    </item>
    <item>
      <title>Re: Stealthwatch Mitigation Actions</title>
      <link>https://community.cisco.com/t5/security-analytics/stealthwatch-mitigation-actions/m-p/3497327#M13</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Jeff,&lt;/P&gt;&lt;P&gt;I have managed to put FlowSensor to its correct space in SMC. But I still can't see how the flowsensor categorized each applications on its own. Are there any other configuration needed? &lt;IMG alt="" class="image-1 jive-image" src="https://community.cisco.com/legacyfs/online/fusion/105537_pastedImage_0.png" style="max-width: 1200px; max-height: 900px;" /&gt;&lt;/P&gt;&lt;P&gt;I have set the monitoring port to accept promiscuous mode.&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="jive-image image-2" src="https://community.cisco.com/legacyfs/online/fusion/105538_pastedImage_1.png" style="max-width: 1200px; max-height: 900px;" /&gt;&lt;/P&gt;&lt;P&gt;Still unclassified hmm&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 22 Mar 2017 04:55:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/security-analytics/stealthwatch-mitigation-actions/m-p/3497327#M13</guid>
      <dc:creator>Andryan Viryadi Tanamir</dc:creator>
      <dc:date>2017-03-22T04:55:14Z</dc:date>
    </item>
  </channel>
</rss>

