Security Analytics

cancel
Showing results for 
Search instead for 
Did you mean: 
cancel

Cisco CyberSecurity


Welcome to the Security Analytics Board!

Please take a look at our Stealthwatch Information Hub and our Stealthwatch Use Cases.

Forum Posts

We are getting alarms related to the "UDP Received" security event. After checking the flows, it is Microsoft Teams traffic the one triggering the security event. Is it possible to turno of this security event for traffic using a specific set of port...

When using Data Store, "alerts" are triggered, but there are many false positives.While "alarms" can be tuned using HostGroups and Policies, is there a way to tune "alerts"?

s.moriyama by Frequent Visitor
  • 369 Views
  • 1 replies
  • 0 Helpful votes

Hello.Could you tell me if it's possible to add a second network interface to the Flow Sensor virtual machine? It's been running for a while and connected to Manager.Simply adding a new interface in vCenter and then rebooting the VM didn't help. The ...

Hello Team,In Anomaly Core Events, we can control events using the "When Host is Source" option. However, for "When Host is Target," the option is not available, meaning in anomaly category we can only control source host groups and not target host g...

anupbhande by Community Member
  • 275 Views
  • 0 replies
  • 0 Helpful votes

Hi,I configured a CSE for alerting everytime a TLS connection using a version lower than 1.3 is made. I'm getting the flow alerts but I cannot see any URL information that helps me identifying which particular URL is not compliant. Is there any way t...

Hello,    Currently I am facing the following issue. I have a cisco flow collector and I successfuly I register it to the Stealthwatch SMC. I can see it from the central system manager but with the status "Data Store not Configured". If I click on th...

Top Solution Authors