Security Analytics

cancel
Showing results for 
Search instead for 
Did you mean: 
cancel

Cisco CyberSecurity


Welcome to the Security Analytics Board!

Please take a look at our Stealthwatch Information Hub and our Stealthwatch Use Cases.

Forum Posts

Hi Team I trying configure StealthWatch Failure on Two SMC Primary and secondary, I follow all steps under the Online help tool.I have Trial License full, and start Failure mode by Seconday SMC: Both SMC* Have Trial License OK I start Failure test un...

01.JPG 02.JPG 03.JPG 04.JPG
josimaru85 by Spotlight
  • 2952 Views
  • 5 replies
  • 0 Helpful votes

Hi,I am not a true licensing guru when it comes to stealthwatch. I know up to 250 exporters that will be close to 4,500 flows per second. But is there a true calculator out there where you can plug in the number of switches/exporters to determine the...

anson-bates by Frequent Visitor
  • 10712 Views
  • 4 replies
  • 0 Helpful votes

Hello everyone, We will be forwarding ISE logs to our SEIM (Helix) I wanted to know what are the top 5-10 logs I should be alerting on? I need to put together an action plan so I cant do that for all the logs. Thankssecurity, Stealthwatch

AK50 by Visitor
  • 980 Views
  • 1 replies
  • 0 Helpful votes

unable to launch ASDM please assistWarning: Potential Security Risk AheadFirefox detected a potential security threat and did not continue to . If you visit this site, attackers could try to steal information like your passwords, emails, or credit ca...

hi, i have a question what happens when you exceeded the limit of the licensestealthwatch stops to records that the flows that pass the limit?can someone upgrade to a bigger frl license - can be the same virtual appliance?thanks for the help, best re...

Hi, we have a Stealthwatch 7 deployed. We send the events to QRadar and in QRadar we receive this kind of log: (...)<110>Mar 04 14:23:01 vap11039 StealthWatch[4925]: LEEF:2.0|Lancope|Stealthwatch|6.8|51|0x7C|src=10.90.7.10|dst=0.0.0.0|dstPort=|proto=...

mbrogioni by Community Member
  • 4134 Views
  • 6 replies
  • 0 Helpful votes

Hi all, I am using Stealthwatch Management Console and Flow Collector Version 7.0.2 with CTA enabled in both devices. I am unable to detect malware in the Host CTA window but able to view malware traffic in SMC. I am using router 4451-X model to expo...

VamsiKrishna by Frequent Visitor
  • 1255 Views
  • 1 replies
  • 0 Helpful votes

I have a problem with flow rate license ordering. I cant find a good document or ordering guide for this license. I have read in stealthwatch datasheet that flow rate license defines the volume of flows that may be collected and is licensed on the ba...

mina.zeinali by Frequent Visitor
  • 16672 Views
  • 8 replies
  • 5 Helpful votes