Security Analytics

cancel
Showing results for 
Search instead for 
Did you mean: 
cancel

Cisco CyberSecurity


Welcome to the Security Analytics Board!

Please take a look at our Stealthwatch Information Hub and our Stealthwatch Use Cases.

Forum Posts

Hello Everyone,I have SMC 2210, FC 4210, FS 3210 in my network. Stealthwatch 7.3.1 is running on all the appliances.Quick overview of problem:I am not seeing any traffic being reported on interfaces that are being monitored on the switches (exporters...

HelloI have such kind of problem with stealthwatch.I Configured flexible netflow on Cisco cisco WS-C3850  Version 16.3.8 I added 2 lines in flow record config #match datalink mac source address input#match datalink mac destination address input Cisco...

stealthwatch  packet capture.JPG stealthwatch.JPG
LevanB by Level 1
  • 730 Views
  • 0 replies
  • 0 Helpful votes

I saw that with Stealthwatch 7.3 ERSPAN support has been added to the Flow Sensor. ERSPAN (Encapsulated Remote Switch Port Analyzer) support has been added to the Flow Sensor to increase versatility. Now, it also offers visibility improvements throug...

scvvuuren by Level 1
  • 2560 Views
  • 2 replies
  • 0 Helpful votes

Hello Folks,I'm running into a problem, when trying to delete the IP settings of an interface of a netflow collector via the cisco stealthwatch central managment applicance configuration webinterface.  The interface "eth1" has an configured IP adress...

stealtwatch ip problem.png

Resolved! SNMP OIDs

Dear Cisco Support,  I want to setup the following monitoring : for Modem and SIM card for the following commands :  Sh cell 0/1/0 security (SIM Status = xxx)Sh cell 0/2/0 security (SIM Status = xxx)Sh cell 0/1/0 hardware (Modem Status = xxx)Sh cell ...

Hi all, I did hit a false positive alarm today: a wireless AP was a source of 'suspect data hoarding' from a WLC.I wanted to disable this core event in this case, but not sure what would be the best way to do so. Ideally, I want to disable this event...

Bart G by Level 1
  • 1284 Views
  • 1 replies
  • 0 Helpful votes

Hi all, I have a question about host group configurations and conflicting baseline configuration. If I understand correctly the 'Enable baselining for Hosts in this Group' controls if hosts are baselined individually or if a baseline is taken for the...

Bart G by Level 1
  • 1811 Views
  • 1 replies
  • 0 Helpful votes

We recently notice on our ISR router that an access list was added to our VTY terminal connection lines. The ip addresses were, 94.102.56.181 and 185.158.249.22. We didn't add them that we can remember. In the config we have 2 usernames being "cisco"...

j-corzatt by Level 1
  • 1206 Views
  • 3 replies
  • 0 Helpful votes