Security Analytics

cancel
Showing results for 
Search instead for 
Did you mean: 
cancel

Cisco CyberSecurity


Welcome to the Security Analytics Board!

Please take a look at our Stealthwatch Information Hub and our Stealthwatch Use Cases.

Forum Posts

Hello Team,In Anomaly Core Events, we can control events using the "When Host is Source" option. However, for "When Host is Target," the option is not available, meaning in anomaly category we can only control source host groups and not target host g...

anupbhande by Community Member
  • 84 Views
  • 0 replies
  • 0 Helpful votes

When using Data Store, "alerts" are triggered, but there are many false positives.While "alarms" can be tuned using HostGroups and Policies, is there a way to tune "alerts"?

We are getting alarms related to the "UDP Received" security event. After checking the flows, it is Microsoft Teams traffic the one triggering the security event. Is it possible to turno of this security event for traffic using a specific set of port...

Hello,    Currently I am facing the following issue. I have a cisco flow collector and I successfuly I register it to the Stealthwatch SMC. I can see it from the central system manager but with the status "Data Store not Configured". If I click on th...

I need to use on-prem SAL to increase FMC events retention on SNA and need to provide high availability between two data centers for my deployment. i also have have cisco telemetry broker. Would it be the same if 1- i configured ftd syslog to point t...

AAA184 by Level 2
  • 582 Views
  • 1 replies
  • 0 Helpful votes
Unanswered Topics