Security Analytics

cancel
Showing results for 
Search instead for 
Did you mean: 
cancel

Cisco CyberSecurity


Welcome to the Security Analytics Board!

Please take a look at our Stealthwatch Information Hub and our Stealthwatch Use Cases.

Forum Posts

I see that the Stealthwatch SMC GUI (7.2) supports MFA via Radius - but looking at ways to limit access to other components such as the CLI on the SMC, as well as the CLI or GUI on the Flow Collectors or Flow Sensors? Does Stealthwatch support the co...

reheindel by • Level 2
  • 2874 Views
  • 2 replies
  • 0 Helpful votes

Hi, One of our customer has purchased VM editions of SMC, FC and FS appliances and 25000 flows licenses. We found that we have different models of VM appliances like SMCVE, SMC2000VE and FCVE,FCVE2000. I found that these specs are based on the host c...

Good Day I recently enabled syslogs from a bluecoat proxy into Stealthwatch.I can see some URL data for users so on the surface it does seem good.I did notice in the log file though some errors. FC01:~# tail -f /lancope/var/sw-flow-proxyparser/logs/s...

scvvuuren by • Level 1
  • 1963 Views
  • 1 replies
  • 0 Helpful votes

Things appeared to go sideways yesterday (02/10) with regard to the data in the SLIC feed - as we received 40+ alerts of C&C activity as users were browsing to www.google.com - the destination IPs were what is expected for Google The destination C&C ...

reheindel by • Level 2
  • 2354 Views
  • 2 replies
  • 0 Helpful votes

(this might mean that someone trying to fool you or steal any info you send to the server)the above message appeared on the client side when using FTD decrypt-resigned, is there any one can help solving that issue .