cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2844
Views
5
Helpful
3
Replies

Is Cisco Stealthwatch separate from Cisco AMP?

UncleJP
Level 1
Level 1

Is Cisco Stealthwatch separate from Cisco AMP? Or, is it just another part of Cisco AMP, like WSA and ESA?

 

Any input is appreciated.

1 Accepted Solution

Accepted Solutions

Hi,
Stealthwatch is separate from AMP, it provides visibility and network traffic analysis.
Stealthwatch is not another part of AMP like ESA or WSA.

HTH

View solution in original post

3 Replies 3

Hi,
Stealthwatch is separate from AMP, it provides visibility and network traffic analysis.
Stealthwatch is not another part of AMP like ESA or WSA.

HTH

I think where this might be confusing is AMP for Networks instead of AMP for Endpoints.

The brochure information for AMP for Networks seems identical to Stealthwatch, so it's really confusing.

(Cisco renamed Stealthwatch, so I'm probably calling it the wrong thing)

 

Marvin Rhoads
Hall of Fame
Hall of Fame

AMP for Networks and AMP for Endpoints ("Cisco Secure Endpoint") both use components of Threatgrid in the backend to perform analysis or previously unseen files. They can only act on what they see passing through the firewall (mostly in plain text) or being acted upon by the endpoint.

Stealthwatch ("Cisco Secure Analytics") is a network detection and response solution that uses sensor information (primarily Netflow) to monitor and analyze the network comprehensively. It uses a much more advanced set of machine learning and artificial intelligence capabilities to draw inferences about behavior and threats based on analysis of that information. (And of course it's "reassuringly expensive" to account for that.)

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card