XDR Microsoft Windows Endpoint Target
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-09-2024 02:28 PM
Is there any additional documentation (blogs, webinars, etc) beyond Microsoft Windows Endpoint Target (cisco.com) on how to set up a Windows Endpoint target in XDR? Is it possible to target internal endpoints? I am under the impression that it would require the use of a Remote appliance, like a HTTP Endpoint, but that's not an option.
Thanks!
- Labels:
-
Endpoint Security
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-09-2024 03:03 PM
There isnt an on prem option for XDR. Its all cloud.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-10-2024 02:21 PM
Tracking the XDR option/profile for NVM but looking for more guidance on configuring a Microsoft Windows Endpoint Target. Guessing it needs a public IP address?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-10-2024 02:44 PM
That's got nothing to do with NVM ("Network Visibility Monitoring"). NVM is the client piece that grabs netflow for all processes that communicate over the network and sends it to the cloud.
For XDR you can only use the supplied "NVM Cloud Default Profile".
If you need an Automate Target, it has to be accessible from their cloud... or if its on-prem, and can be HTTP or Terminal access, you can deploy a "Remote" (in XDR under Automate/Advanced/Remotes).
