Presented by: McClain Marchman, Cisco Stealthwatch Advanced Services Network Consulting Engineer, Cisco Security Business Group
Reduce operator overhead, advance Stealthwatch optimization, and receive more accurate alarming on meaningful events? Yes, you can!
The Stealthwatch Host Group Automation (HGA) Service gives you a logical means of categorizing network assets for improved visibility and control. It enables the classification of your host groups from third-party data feeds so you can keep them synchronized with your network infrastructure.
McClain Marchman shows how you can use HGA to:
Tackle dynamic server behavior that consistently changes IP addresses and configure Stealthwatch to apply policies to these automated, dynamic, host groups.
Reduce excess consumption of your team’s resources by decreasing overall cost to operate Stealthwatch and by decreasing false positive alarms.
Manage integrations proactively with authoritative IP data sources such as IPAMs, CMDBs, and threat feeds.
McClain Marchman is a Cisco Stealthwatch Advanced Services Network Consulting Engineer in the Security Business Group. He is a part of the team that creates new and exciting custom integration solutions for customers such as the SIEM integration, HGA integration, and the Proxy integration service. McClain joined Cisco via Lancope in 2015 as a Technical Support Engineer. He holds a B.S. in Computer Science from Kennesaw State University, Georgia.
Hi,I have a deployment with 2 nodes. I had to reinstall a broken node. When I joined the new node to the deployment, sync finished successfully but authentication logs were not synchronised. How to force ISE to send all historical authentication logs from...
Hi, I have established a VPN between Cisco ASA and a Fortinet firewall. Phase 1 and Phase 2 are up and traffic is passing but after a while the VPN phase 2 drops and traffic is not able to be passed without logging/rebooting the tunnel manually...
Hi,I want to do the below setupSITE TO SITE VPN PRIORITYPriority 1 site1 192.168.2.0/24 site2 192.168.3.0/24Priority 2 site1 192.168.2.0/24 site3 192.168.4.0/24My question since the source (192.168.2.0/24) is same the traffic destined to 192.168.4.0/24 wi...