Cisco Stealthwatch Use Case Workshop: SIEM Integration with Cisco Stealthwatch

Available Languages

Download Options

  • PDF
    (151.2 KB)
    View with Adobe Reader on a variety of devices
Updated:June 16, 2020

Bias-Free Language

The documentation set for this product strives to use bias-free language. For the purposes of this documentation set, bias-free is defined as language that does not imply discrimination based on age, disability, gender, racial identity, ethnic identity, sexual orientation, socioeconomic status, and intersectionality. Exceptions may be present in the documentation due to language that is hardcoded in the user interfaces of the product software, language used based on RFP documentation, or language that is used by a referenced third-party product. Learn more about how Cisco is using Inclusive Language.

Available Languages

Download Options

  • PDF
    (151.2 KB)
    View with Adobe Reader on a variety of devices
Updated:June 16, 2020

Table of Contents

 

 

Use Case Workshop overview

Use Case Workshops are hands-on, instructor-led courses focused on specific use case outcomes in Cisco Stealthwatch® Enterprise. The workshops are designed to help you quickly identify and investigate common threats and to provide effective workflows so that you can fully understand Stealthwatch capabilities.

In this workshop, you’ll work through a series of activities that focus on the use of SIEMs and Stealthwatch to provide insights into your network. In a lab environment, you will learn how to leverage the insights gained by combining the network behavioral context provided by Stealthwatch with the Splunk SIEM.

This workshop is intended to be interactive and engaging. You are encouraged to ask questions, respond to questions, and share best practices and ideas.

After taking this workshop, you should be able to:

     Describe the advantages of integrating Stealthwatch with a SIEM.

     View SIEM data in Stealthwatch by creating a SIEM external lookup option.

     Configure the Splunk SIEM to accept Stealthwatch syslog entries through the Response Management feature.

     Explore a Stealthwatch API integration with Splunk.

Workshop duration

Approximately 2 to 3 hours.

Cisco Capital

Flexible payment solutions to help you achieve your objectives

Cisco Capital makes it easier to get the right technology to achieve your objectives, enable business transformation and help you stay competitive. We can help you reduce the total cost of ownership, conserve capital, and accelerate growth. In more than 100 countries, our flexible payment solutions can help you acquire hardware, software, services and complementary third-party equipment in easy, predictable payments. Learn more.

For more information

Contact the Cisco Stealthwatch Learning Services team at stealthwatch-training@cisco.com.

Learn more