Hi Experts, I got a question ! If we have sltealthwatch configured with CTA which can get us C&C flow. Now do we really require SLIC feature? Regards, Jay
Hi Experts, I got a question ! If we have sltealthwatch configured with CTA which can get us C&C flow. Now do we really require SLIC feature? Regards, Jay
Hello Team, I have a Cisco SNA deployment which is running on 7.4.0, now when the event trafficlogs are forwarded to any of the syslog or siem servers example IBMQradar / Syslog-ng i see the destination ip address coming as 0.0.0.0 which is kind of n...
Stealthwatch flow duration time declare the sesion establishment timing for perticular source ip to destination ip and service.If the connection will stop for 5 min stealthwatch will show the session is stoped and show the time accordingly in flow du...
We have a "Exfiltration" alarm that triggers between several source hosts and a single target host. For example, I've created a host group A for the source hosts and host group B for the target hosts.How can I stop the "Exfiltration" alarm from trigg...
Hi there, Recently I integrated CISCO identity service engine 3.0.0.458 with stealth watch 7.3.0, the Active directory service are enabled & I get to see the users in monitor section of stealth watch management center , when i open the user for bet...
Hi,1. how can I clear non active allarms manually?2. how can I acknowledge allarms manually?
How can I exclude or change Virtual-Access? There are dynamically tunnels and I can't set bandwidth
Hello, Does anybody know if are there any way to receive a message on SCA when a Sensor came back online after being down. Thanks
Hello, When I'm trying to send post (for example add host group) to SNA 7.4.1 API, I received 401 unauthorized error. All get requests are fine. Authentication is passed and cookies are the correct one when I tried to post. Is there something I shoul...
Hi all, Based on Stealthwatch Data Sheet, it was mentioned that there are two versions of Flow Collector HW and VM. Let's take the VM version with this part number: L-ST-FC-VE-K9 The questions should be asked here are: Using HW or VM version of the f...
Hello, In the past SteatchWatch developed various features to ingest the logs from Proxy (using Proxy Ingest) or even sniff the URLs from the network (using Flow Sensor). This was before Cisco time. Can you share any recent news/features on adding th...
Can anyone help me to recover the password of cisco 4300 series?
I have Stealtwatch 7.4.1, and I noticed that SMC can't get snmp data from different asa devices, I see that exchange is going, but on the exorters all ports are named as ifIndex. Asa devices have the same ios, the same config
HiI have an issue with stealthwatch v7.3. My smc no show the name of the interfaces for exporters. It usually display ifindex-24567xx --- My config is match datalink mac source address inputmatch datalink mac destination address inputmatch ipv4 tosma...
In the current version of Stealthwatch (Cisco Secure Network Analytics), is there a feature to take an action in order to block automatically threat, suspicious behavior of an IP address ?
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide
| Subject | Author | Posted |
|---|---|---|
| 07-09-2026 04:56 PM | ||
| 06-04-2026 11:28 PM | ||
| 05-24-2026 11:01 PM | ||
| 04-23-2026 12:56 AM | ||
| 03-08-2026 11:12 PM |