Security Analytics

cancel
Showing results for 
Search instead for 
Did you mean: 
cancel

Cisco CyberSecurity


Welcome to the Security Analytics Board!

Please take a look at our Stealthwatch Information Hub and our Stealthwatch Use Cases.

Forum Posts

Resolved! ETA Analytics

If a infrastructure device (router, switch) is capable and enabled for Encrypted Traffic Analysis - will east/west traffic within an environment be reported on? It was my understanding that ETA was specifically for traffic between the Inside and Outs...

reheindel by Level 3
  • 2968 Views
  • 2 replies
  • 0 Helpful votes

Hi Team I trying configure StealthWatch Failure on Two SMC Primary and secondary, I follow all steps under the Online help tool.I have Trial License full, and start Failure mode by Seconday SMC: Both SMC* Have Trial License OK I start Failure test un...

01.JPG 02.JPG 03.JPG 04.JPG
josimaru85 by Spotlight
  • 3098 Views
  • 5 replies
  • 0 Helpful votes

Hi,I am not a true licensing guru when it comes to stealthwatch. I know up to 250 exporters that will be close to 4,500 flows per second. But is there a true calculator out there where you can plug in the number of switches/exporters to determine the...

anson-bates by Frequent Visitor
  • 10950 Views
  • 4 replies
  • 0 Helpful votes

Hello everyone, We will be forwarding ISE logs to our SEIM (Helix) I wanted to know what are the top 5-10 logs I should be alerting on? I need to put together an action plan so I cant do that for all the logs. Thankssecurity, Stealthwatch

AK50 by Visitor
  • 1042 Views
  • 1 replies
  • 0 Helpful votes

unable to launch ASDM please assistWarning: Potential Security Risk AheadFirefox detected a potential security threat and did not continue to . If you visit this site, attackers could try to steal information like your passwords, emails, or credit ca...

hi, i have a question what happens when you exceeded the limit of the licensestealthwatch stops to records that the flows that pass the limit?can someone upgrade to a bigger frl license - can be the same virtual appliance?thanks for the help, best re...

Hi, we have a Stealthwatch 7 deployed. We send the events to QRadar and in QRadar we receive this kind of log: (...)<110>Mar 04 14:23:01 vap11039 StealthWatch[4925]: LEEF:2.0|Lancope|Stealthwatch|6.8|51|0x7C|src=10.90.7.10|dst=0.0.0.0|dstPort=|proto=...

mbrogioni by Community Member
  • 4556 Views
  • 6 replies
  • 0 Helpful votes
Unanswered Topics