02-17-2020
06:42 PM
- last edited on
02-20-2020
03:31 PM
by
Hilda Arteaga
To participate in this event, please use the button below to ask your questions
Ask questions from Tuesday 18th to Friday 21st of February, 2020
**Helpful votes Encourage Participation! **
Please be sure to rate the Answers to Questions
02-20-2020 11:17 AM
Hi Ben, Ira and Adi
Thanks for your great session, we learned a lot last Tuesday. Please help to clarify the remaining questions:
02-20-2020 01:49 PM - edited 02-20-2020 01:49 PM
> If you use the automated tools to apply changes is there a change log? Talking about the click/change is here any way to get a change report each day for example?
No, this is currently not supported. If detailed journaling is needed, we recommend using the notes features in the casebook tool to track this kind of activity. If you just want to be able to see the list of all things that have been added to a blocklist, the lists themselves are still available in their usual places in each products' own interface.
02-20-2020 11:17 AM
02-20-2020 02:03 PM
@ciscomoderator wrote:
- You can see historic activity, but can you see real time activity for a specific issue? For instance, in one scenario you think you have put the resolution in place but management wants to know it has definitely worked
Many sightings will report if the attempt was allowed or not. So for example if you are investigating a domain, and Umbrella returns a sighting on that domain, it may say in the "resolution" column that the connection was allowed. Then if you block that domain in Umbrella, you can pivot into Umbrella to see the blocklist and cofirm that the domain was added, and you can also test a conneciton to that domain and see that it was blocked, and in the Threat Response interface if you investigate the domain again, you will see a new sighting on the domain with a resolution of "blocked". see the example image below:
02-20-2020 11:24 AM
Another challenge for you guys ‘building a zero downtime network’, I am aware certain devices can but patched/upgraded with zero downtime for example but they are high end devices, others have failover. What are the lower end options or alternatives eg. booting part of a switch stack at a time?
02-20-2020 02:04 PM
@ciscomoderator wrote:
Another challenge for you guys ‘building a zero downtime network’, I am aware certain devices can but patched/upgraded with zero downtime for example but they are high end devices, others have failover. What are the lower end options or alternatives eg. booting part of a switch stack at a time?
Threat Response is a cloud-only service; you do not have to patch it. Problem solved :)
02-20-2020 03:33 PM
Thanks for helping to clarify these questions Ben
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: