<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Excluding an alarm between two host groups in Security Analytics</title>
    <link>https://community.cisco.com/t5/security-analytics/excluding-an-alarm-between-two-host-groups/m-p/4816957#M949</link>
    <description>&lt;P&gt;I tried the&amp;nbsp;&lt;STRONG&gt;Relationship Alarm&lt;/STRONG&gt; but I found that to be too generic as you said. I instead created a role policy which says to Ignore alarm when&amp;nbsp;&lt;STRONG&gt;A&lt;/STRONG&gt; is source and "On+Alarm" when &lt;STRONG&gt;A&lt;/STRONG&gt; is target. Its too bad though there is no definitive way to make a policy to ignore an alarm between Source &lt;STRONG&gt;A&lt;/STRONG&gt; and Target &lt;STRONG&gt;B&lt;/STRONG&gt;.&lt;/P&gt;</description>
    <pubDate>Tue, 18 Apr 2023 13:35:22 GMT</pubDate>
    <dc:creator>stipend</dc:creator>
    <dc:date>2023-04-18T13:35:22Z</dc:date>
    <item>
      <title>Excluding an alarm between two host groups</title>
      <link>https://community.cisco.com/t5/security-analytics/excluding-an-alarm-between-two-host-groups/m-p/4806931#M932</link>
      <description>&lt;P&gt;We have a "Exfiltration" alarm that triggers between several source hosts and a single target host. For example, I've created a host group A for the source hosts and host group B for the target hosts.&lt;/P&gt;&lt;P&gt;How can I stop the "Exfiltration" alarm from triggering between the two host groups?&amp;nbsp; I tried relationship, role, and single host policy but all of them only allow me to specify the action to take for a single host group.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="stipend_0-1680545999096.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/180821i61F9C135A88BD5E4/image-size/medium?v=v2&amp;amp;px=400" role="button" title="stipend_0-1680545999096.png" alt="stipend_0-1680545999096.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Is there any way to specify when A host group is source and when B host group is Target to ignore the alarm?&lt;/P&gt;</description>
      <pubDate>Mon, 03 Apr 2023 18:23:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/security-analytics/excluding-an-alarm-between-two-host-groups/m-p/4806931#M932</guid>
      <dc:creator>stipend</dc:creator>
      <dc:date>2023-04-03T18:23:29Z</dc:date>
    </item>
    <item>
      <title>Re: Excluding an alarm between two host groups</title>
      <link>https://community.cisco.com/t5/security-analytics/excluding-an-alarm-between-two-host-groups/m-p/4814615#M942</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1468517"&gt;@stipend&lt;/a&gt;&amp;nbsp; - Are both of the host groups in this example under Inside Hosts?&lt;/P&gt;
&lt;P&gt;Before we get too much further, let's skip the &lt;STRONG&gt;Exfiltration&lt;/STRONG&gt; Alarm because it is a Category Alarm. Instead, let's talk about the &lt;STRONG&gt;Suspect Data Loss&lt;/STRONG&gt; Security &lt;EM&gt;Event&lt;/EM&gt; that is responsible for it.&amp;nbsp; (For a discussion on the difference between Category Alarms and Security Events see &lt;A href="https://community.cisco.com/t5/security-analytics/cisco-stealthwatch-and-never-trigger-alarm-when-less-than/td-p/4797226" target="_self"&gt;this thread&lt;/A&gt;)&lt;/P&gt;
&lt;P&gt;In &lt;A title="Cisco Secure Network Analytics: Security Events and Alarm Categories 7.4.2" href="https://www.cisco.com/c/dam/en/us/td/docs/security/stealthwatch/management_console/securit_events_alarm_categories/7_4_2_Security_Events_and_Alarm_Categories_DV_2_1.pdf#%5B%7B%22num%22%3A486%2C%22gen%22%3A0%7D%2C%7B%22name%22%3A%22XYZ%22%7D%2C72%2C741.75%2C0%5D" target="_blank" rel="noopener"&gt;The 7.4.2 documentation for Alarms &amp;amp; Events covering the Suspect Data Loss event&lt;/A&gt; the &lt;STRONG&gt;Suspect Data&lt;/STRONG&gt; &lt;STRONG&gt;Loss&lt;/STRONG&gt; event is explicitly looking for traffic between inside and outside host groups.&lt;/P&gt;
&lt;P&gt;--jg&lt;/P&gt;</description>
      <pubDate>Fri, 14 Apr 2023 16:38:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/security-analytics/excluding-an-alarm-between-two-host-groups/m-p/4814615#M942</guid>
      <dc:creator>jamegill</dc:creator>
      <dc:date>2023-04-14T16:38:20Z</dc:date>
    </item>
    <item>
      <title>Re: Excluding an alarm between two host groups</title>
      <link>https://community.cisco.com/t5/security-analytics/excluding-an-alarm-between-two-host-groups/m-p/4814622#M944</link>
      <description>&lt;P&gt;Sorry not sure why I put &lt;STRONG&gt;Exfiltration&lt;/STRONG&gt;. The alarm is actually for&amp;nbsp;&lt;STRONG&gt;Slow Connection Flood&lt;/STRONG&gt;.&lt;/P&gt;&lt;P&gt;Yes both these host groups are in Inside Hosts.&amp;nbsp; They are both inside host groups that communicate with each other and have legitimate traffic. I would like exclude the Slow Connection Flood between these two groups.&lt;/P&gt;</description>
      <pubDate>Fri, 14 Apr 2023 16:50:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/security-analytics/excluding-an-alarm-between-two-host-groups/m-p/4814622#M944</guid>
      <dc:creator>stipend</dc:creator>
      <dc:date>2023-04-14T16:50:59Z</dc:date>
    </item>
    <item>
      <title>Re: Excluding an alarm between two host groups</title>
      <link>https://community.cisco.com/t5/security-analytics/excluding-an-alarm-between-two-host-groups/m-p/4814651#M946</link>
      <description>&lt;P&gt;Ok, you have a couple of options. As discussed &lt;A href="https://community.cisco.com/t5/security-analytics/cisco-stealthwatch-and-never-trigger-alarm-when-less-than/td-p/4797226" target="_self"&gt;here&lt;/A&gt; the configuration option for &lt;EM&gt;When host is&lt;/EM&gt; [target | source] can be set to just "on" instead of "on + alarm" so the individual event does not create an alarm for each event, but rather only for the Category Alarm.&lt;/P&gt;
&lt;P&gt;The next option would be to create a &lt;STRONG&gt;Relationship Alarm&lt;/STRONG&gt; for these two hosts.&amp;nbsp; I will come back with a longer post later on how to do that (fact: Relationshop Alarms are my favorite feature of SNA that nobody really knows about).&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Quick start, though -&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;create a new Network Diagram (look under the Dashbaords menu), add just the host groups in question&lt;/LI&gt;
&lt;LI&gt;create an edge (line) between the groups.&amp;nbsp; tweak the diagram to suit your liking (or don't, you can edit it later)&lt;/LI&gt;
&lt;LI&gt;save the diagram&lt;/LI&gt;
&lt;LI&gt;right-click on the line between the groups, select Policy Management&lt;/LI&gt;
&lt;LI&gt;You're now editing the policy that only applies to the traffic between the two groups&lt;/LI&gt;
&lt;LI&gt;click on Select Events and choose the individual policies for behaviors you want to monitor for here.&lt;BR /&gt;(yes, the policy types are more general than with the Core Policies, but you can get pretty close)&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;--jg&lt;/P&gt;</description>
      <pubDate>Fri, 14 Apr 2023 17:30:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/security-analytics/excluding-an-alarm-between-two-host-groups/m-p/4814651#M946</guid>
      <dc:creator>jamegill</dc:creator>
      <dc:date>2023-04-14T17:30:38Z</dc:date>
    </item>
    <item>
      <title>Re: Excluding an alarm between two host groups</title>
      <link>https://community.cisco.com/t5/security-analytics/excluding-an-alarm-between-two-host-groups/m-p/4816957#M949</link>
      <description>&lt;P&gt;I tried the&amp;nbsp;&lt;STRONG&gt;Relationship Alarm&lt;/STRONG&gt; but I found that to be too generic as you said. I instead created a role policy which says to Ignore alarm when&amp;nbsp;&lt;STRONG&gt;A&lt;/STRONG&gt; is source and "On+Alarm" when &lt;STRONG&gt;A&lt;/STRONG&gt; is target. Its too bad though there is no definitive way to make a policy to ignore an alarm between Source &lt;STRONG&gt;A&lt;/STRONG&gt; and Target &lt;STRONG&gt;B&lt;/STRONG&gt;.&lt;/P&gt;</description>
      <pubDate>Tue, 18 Apr 2023 13:35:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/security-analytics/excluding-an-alarm-between-two-host-groups/m-p/4816957#M949</guid>
      <dc:creator>stipend</dc:creator>
      <dc:date>2023-04-18T13:35:22Z</dc:date>
    </item>
    <item>
      <title>Re: Excluding an alarm between two host groups</title>
      <link>https://community.cisco.com/t5/security-analytics/excluding-an-alarm-between-two-host-groups/m-p/4817129#M951</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1468517"&gt;@stipend&lt;/a&gt; ... good work, you're on the right track.&amp;nbsp; Here are a couple of suggestions ...&lt;BR /&gt;&lt;BR /&gt;For &lt;STRONG&gt;Slow Connection Flood&lt;/STRONG&gt; consider turning the "when host is source" to "on" for the Inside Hosts default policy.&amp;nbsp;&amp;nbsp; Because you shouldn't see this very much between inside hosts (as discussed in more detail in &lt;A href="https://www.cisco.com/c/dam/en/us/td/docs/security/stealthwatch/management_console/securit_events_alarm_categories/7_4_2_Security_Events_and_Alarm_Categories_DV_2_1.pdf#%5B%7B%22num%22%3A426%2C%22gen%22%3A0%7D%2C%7B%22name%22%3A%22XYZ%22%7D%2C72%2C741.75%2C0%5D" target="_blank" rel="noopener"&gt;the documentation for this alarm&lt;/A&gt;), you probably don't need an alarm for each instance of this event.&amp;nbsp; By setting it to "on" you are still monitoring for this behavior but it will contribute to the &lt;EM&gt;Category&lt;/EM&gt; Alarms for Concern Index, dDoS Source, dDoS Target.&lt;/P&gt;
&lt;P&gt;The&amp;nbsp;&lt;STRONG&gt;Role Policy&lt;/STRONG&gt; approach here is a good approach if you are only seeing the alarm on a subset of your hosts. By applying that policy to the effected subset of hosts (Host Groups) you can again decide to set the event to "on" or "on+alarm", and you can also adjust the the thresholds in the event configuration to that Role Policy to override the setting of the Inside Hosts &lt;STRONG&gt;Default&lt;/STRONG&gt; policy.&lt;/P&gt;
&lt;P&gt;The concept of building policies with specific application to&amp;nbsp; (or excemption for) specific source/destination host groups is a concept which has come up before, so I have added this thread to the internal discussion around that topic.&amp;nbsp; Thank you for enhancing that conversation.&lt;/P&gt;
&lt;P&gt;--jg&lt;/P&gt;</description>
      <pubDate>Tue, 18 Apr 2023 18:14:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/security-analytics/excluding-an-alarm-between-two-host-groups/m-p/4817129#M951</guid>
      <dc:creator>jamegill</dc:creator>
      <dc:date>2023-04-18T18:14:38Z</dc:date>
    </item>
    <item>
      <title>Re: Excluding an alarm between two host groups</title>
      <link>https://community.cisco.com/t5/security-analytics/excluding-an-alarm-between-two-host-groups/m-p/4817753#M956</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;BR /&gt;For &lt;STRONG&gt;Slow Connection Flood&lt;/STRONG&gt; consider turning the "when host is source" to "on" for the Inside Hosts default policy.&amp;nbsp;&amp;nbsp; Because you shouldn't see this very much between inside hosts (as discussed in more detail in &lt;A href="https://www.cisco.com/c/dam/en/us/td/docs/security/stealthwatch/management_console/securit_events_alarm_categories/7_4_2_Security_Events_and_Alarm_Categories_DV_2_1.pdf#%5B%7B%22num%22%3A426%2C%22gen%22%3A0%7D%2C%7B%22name%22%3A%22XYZ%22%7D%2C72%2C741.75%2C0%5D" target="_blank" rel="noopener"&gt;the documentation for this alarm&lt;/A&gt;), you probably don't need an alarm for each instance of this event.&amp;nbsp; By setting it to "on" you are still monitoring for this behavior but it will contribute to the &lt;EM&gt;Category&lt;/EM&gt; Alarms for Concern Index, dDoS Source, dDoS Target.&lt;P&gt;--jg&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;We do this see this a lot internally. One instance has been the case of just how two groups of servers communicate with each other. The other instance has been employees accessing an internal application through port 443 which triggers the alarm. So far its been false positives but, yeah, we see this frequently. Thanks for your help anyways. I hope an "exemption" feature gets added in the future!&lt;/P&gt;</description>
      <pubDate>Wed, 19 Apr 2023 13:58:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/security-analytics/excluding-an-alarm-between-two-host-groups/m-p/4817753#M956</guid>
      <dc:creator>stipend</dc:creator>
      <dc:date>2023-04-19T13:58:16Z</dc:date>
    </item>
  </channel>
</rss>

