Security Analytics

cancel
Showing results for 
Search instead for 
Did you mean: 
cancel

Cisco CyberSecurity


Welcome to the Security Analytics Board!

Please take a look at our Stealthwatch Information Hub and our Stealthwatch Use Cases.

Forum Posts

Alan Nix has created a great python script to import the Talos Blacklist into Stealthwatch. I have successfully run the script manually. I would like to run the script daily using cron. I used crontab, but I am not sure it actually runs.   Here is th...

Resolved! Stealthwatch

If i purchase 9000 family device and i have got the Stealthwatch service, do i purchase another device that is used to collect flow or follow collector or Stealthwatch is license only?  what is the difference betwee:-                           Cisco ...

HiI have been reading and watching some videos. Looking for some best practices on what alerts to enable - lets to be emailed or sysloged. I watched one video out there, and it was not very helpful. If there were 5 alerts, which would be one.. I know...

tomalexis by Frequent Visitor
  • 1973 Views
  • 1 replies
  • 0 Helpful votes

I need to apply rollup patches on my customer's Stealthwatch management console (SMC) and their flow collector (FC). The documentation on how to apply patches is very good. However, it doesn't explain how to rollback patches in case installing patche...

toyip by Cisco Employee
  • 3077 Views
  • 4 replies
  • 0 Helpful votes

I have a problem in setting up netflow for Cisco Stealthwatch. I've set up the exporter in WLC through GUI, but Stealthwatch didn't show any data. Stealthwatch read the flows from WLC, but no data about the clients. Stealthwatch displayed an error "E...

problem.jpg problem 2.jpg
Trivela by Level 1
  • 4851 Views
  • 2 replies
  • 5 Helpful votes

Hello all,   I setup CTA and ETA with Catalyst9300 and Stealthwatch.How can I confirm that ETA works fine?I uploaded the large file to the web server which has self signed certificate.But no alarm occurred.Should I use real malware? If yes, which mal...

Tsunoda by Visitor
  • 4104 Views
  • 2 replies
  • 0 Helpful votes

Hi,I have issue of security event "Ping Oversized Packet" in Stealthwatch. In documentation I see next: "It searches for ICMP packets that are larger than thestandard size of 90 bytes, either as an ICMP echo request(if the host is the destination of ...

alexander05 by Community Member
  • 2361 Views
  • 0 replies
  • 0 Helpful votes