Skip to main content

Cisco Stealthwatch

cisco-stealthwatch

Version: 1.1
Updated: Jul 06, 2023

Cisco Stealthwatch provides easy to use and comprehensive APIs for reporting, making configuration changes, managing users, exporting data, and more. It offers early access to advanced event capabilities and UI workflows with Analytics, which provides new and effective alerts that require less manual configuration.

Actions

  • List Tags (Enrichment) - Provides access to basic information about the Tags (host groups) in Stealthwatch.
  • Get Tag (Enrichment) - Get details for a specific tag.
  • Get Top Alarming Tags (Enrichment) - Retrieves top alarming tags for a given host type.
  • Get Top Applications (Enrichment) - Search for the top applications with a given criteria.
  • Get Top Hosts (Enrichment) - Search for top hosts with a given criteria.
  • Get Top Ports (Enrichment) - Search for top ports with a given criteria.
  • List Hourly Traffic Tag (Enrichment) - Retrieves the hourly traffic trend for a given host type.
  • List Tenants (Enrichment) - Provides access to basic information about the Tenants (domains) and the Tags (host groups) in the Stealthwatch System.
  • Search Flows (Enrichment) - Perform flow searches using basic criteria such as time range, IP address or range, port/protocols, and host groups.
  • Search Events (Enrichment) - Perform event searches based on the given criteria.

Cisco Stealthwatch in Automation Service and Cloud SOAR

  1. To configure the integration, log into the application, expand the configuration menu in the top right corner by hovering over the gear icon and click Automation.
    cisco-stealthwatch
  2. In the Automation section, on the left menu, click Integrations.
    cisco-stealthwatch
  3. After the list of the integrations appears, search for the integration and click on the row.
  4. The integration details will appear. Click on the "+" button to add new Resource.
    cisco-stealthwatch
  5. Populate all the required fields (*).
  6. Click Save.
  7. To make sure the resource is working, hover over the resource and then click the pencil icon that appears on the right.
    cisco-stealthwatch
  8. Click Test.
    cisco-stealthwatch
  9. You should receive a successful notification in the bottom right corner.
    cisco-stealthwatch

Change Log

  • Aug 04, 2022 - First upload
  • July 6, 2023 (v1.1) - Updated the integration with Environmental Variables
Legal
Privacy Statement
Terms of Use

Copyright © 2024 by Sumo Logic, Inc.