Security Analytics

cancel
Showing results for 
Search instead for 
Did you mean: 
cancel

Cisco CyberSecurity


Welcome to the Security Analytics Board!

Please take a look at our Stealthwatch Information Hub and our Stealthwatch Use Cases.

Forum Posts

I see that the Stealthwatch SMC GUI (7.2) supports MFA via Radius - but looking at ways to limit access to other components such as the CLI on the SMC, as well as the CLI or GUI on the Flow Collectors or Flow Sensors? Does Stealthwatch support the co...

reheindel by Level 1
  • 1844 Views
  • 2 replies
  • 0 Helpful votes

Hi, One of our customer has purchased VM editions of SMC, FC and FS appliances and 25000 flows licenses. We found that we have different models of VM appliances like SMCVE, SMC2000VE and FCVE,FCVE2000. I found that these specs are based on the host c...

Dear CommunityWe're looking for a solution to access to Cognitive Threat Analytics (Stealthwatch Data) from an other Browser, than the Browser used for Cisco Stealthwatch.  Do you have similar situations and maybe a solution for access CTA without th...

ipworxs by Level 1
  • 959 Views
  • 0 replies
  • 0 Helpful votes

December 2: Central Log Management using Cisco Security Analytics and Logging 8am-9:30am PT Cisco Security Analytics and Logging is Cisco’s Central Log Management solution for Network Operations and Security Outcomes. It is delivered both as a cloud ...

November 18: Multicloud security posture and threat management with Stealthwatch Cloud 8am-9:30am PT Cisco Stealthwatch Cloud provides visibility, compliance, threat detection and investigation capabilities across on-premises and cloud environments. ...

Good Day I recently enabled syslogs from a bluecoat proxy into Stealthwatch.I can see some URL data for users so on the surface it does seem good.I did notice in the log file though some errors. FC01:~# tail -f /lancope/var/sw-flow-proxyparser/logs/s...

scvvuuren by Level 1
  • 1321 Views
  • 1 replies
  • 0 Helpful votes

Things appeared to go sideways yesterday (02/10) with regard to the data in the SLIC feed - as we received 40+ alerts of C&C activity as users were browsing to www.google.com - the destination IPs were what is expected for Google The destination C&C ...

reheindel by Level 1
  • 1669 Views
  • 2 replies
  • 0 Helpful votes