Security Analytics

cancel
Showing results for 
Search instead for 
Did you mean: 
cancel

Cisco CyberSecurity


Welcome to the Security Analytics Board!

Please take a look at our Stealthwatch Information Hub and our Stealthwatch Use Cases.

Forum Posts

I need to use on-prem SAL to increase FMC events retention on SNA and need to provide high availability between two data centers for my deployment. i also have have cisco telemetry broker. Would it be the same if 1- i configured ftd syslog to point t...

AAA184 by Level 2
  • 816 Views
  • 1 replies
  • 0 Helpful votes

Hi, As I have configured a CSE to generate an Alarm while a flow is seen between a host and peer, the Alarm outcome is widely different from flows that has seen in the flow search. Can anyone explain the issue or reason behind it?

navidn by Level 2
  • 1074 Views
  • 3 replies
  • 0 Helpful votes

Hi, it appears that the reporting dashboard does not offer an option to generate reports specifically for alarms related to a particular Relationship policy name. Currently, the only available selection seems to cover all relationship events that hav...

navidn by Level 2
  • 548 Views
  • 0 replies
  • 0 Helpful votes

Hello, currently we are facing two data nodes failure from 9 nodes DSN cluster. We already tried to start the failed nodes but SMC returns the following Error:Unable to read database catalogs - cannot start databaseFirst, I would appreciate that if a...

navidn by Level 2
  • 1837 Views
  • 2 replies
  • 0 Helpful votes

Hi, I can't find a proper way to exclude a vulnerability scanner IP from alerts in SCA.  One possible way to solve this (I guess) is to add entity groups for source IP and destination subnets. Afterwards select these entity groups in an Internal Conn...

YZ2 by Frequent Visitor
  • 2187 Views
  • 5 replies
  • 0 Helpful votes
Unanswered Topics
Top Solution Authors