Cisco IQ Getting Started Guide

 
Updated July 23, 2026
PDF
Is this helpful? Feedback

Cisco IQ Getting Started Guide

Introduction

Cisco IQ™ provides customers with enhancements and features designed to improve asset visibility, deliver smarter insights across their environments, and streamline case management. In addition, AI features such as the AI Assistant optimize operational outcomes and the Cisco IQ user experience by providing contextual understanding that empowers you to make proactive, informed decisions and streamline processes for customer engagement and success.

This document provides information about getting started with Cisco IQ and its modules. For more information, see the Cisco IQ Release Notes and Cisco IQ Frequently Asked Questions documents.

Onboarding

Prerequisites

Ensure that the following prerequisites are met before using Cisco IQ.

Supported Browsers

Cisco IQ is supported on the latest stable releases of the following browsers:

  • Google Chrome
  • Microsoft Edge
  • Apple Safari
  • Mozilla Firefox

Note: Support is limited to current browser versions and older versions may not provide full functionality or may be unsupported as new updates are released.

Cisco Account

To access Cisco IQ, you must have a Cisco.com account. See Login and Account Help for more information about Cisco accounts.

Account Creation

Creating a New Cisco IQ Account

To create a new Cisco IQ account:

  1. Navigate to Cisco IQ. The Cisco IQ Log In page displays.

    Cisco IQ Log in
    Cisco IQ Log in
  2. Click Create an account.

  3. Enter your Cisco Connection Online (CCO) ID credentials into the Email field.

  4. Click Next.

  5. Enter your Password.

  6. Click Verify. The Create a Cisco IQ Account page displays.

    Create a Cisco IQ Account
    Create a Cisco IQ Account
  7. Enter the unique name you want to use for your organization’s Cisco IQ account in the Enter a company account name field.

  8. Select the primary data storage region.

  9. Click Create account. You are redirected to the Cisco IQ Launchpad.

Migrating CX Cloud Accounts to Cisco IQ

Note: Only Account Administrators can migrate existing CX Cloud accounts to Cisco IQ.

If you have an existing CX Cloud account, you can migrate existing CX Cloud data to Cisco IQ. The following data is automatically migrated from the existing CX Cloud account:

  • Users and user groups (excludes partner users and groups)
  • Contracts
  • Cloud data source addition for Intersight, Webex, Software-Defined Wide Area Network (SD-WAN), and Meraki

Note: To ensure a smooth transition and to gain more accurate insights from Cisco IQ’s personalized, predictive, and proactive AI-powered intelligence, consider validating and organizing your CX Cloud account data prior to migration.

Warning: If you create a new Cisco IQ account without migrating CX Cloud data, you cannot migrate CX Cloud account data at a later time.

Note: Only one CX Cloud account can be migrated at a time. If you need to migrate additional accounts, repeat the steps outlined in this section.

To migrate an existing CX Cloud account:

  1. Navigate to Cisco IQ. The Cisco Log in page displays.

  2. Click Create an account.

  3. Enter your CCO ID credentials into the Email field.

  4. Click Next.

  5. Enter your Password.

  6. Click Verify. The Create a Cisco IQ Account page displays.

    Select CX Cloud Account
    Select CX Cloud Account
  7. Select the CX Cloud account you want to migrate data from.

  8. Enter the unique name you want to use for your organization’s Cisco IQ account.

Note: The data storage region from the original account is auto-populated and migrated to the Cisco IQ company account. To change the data storage region, you must create a new Cisco IQ company account.

  1. Click Create account and migrate data. The Migration Status page displays.

    The Migration Status page displays the completion status of the data being migrated to Cisco IQ. The following statuses are available:

    Migration Status
    Migration Status
    • In progress: Data is in the process of being migrated

    • Completed: Migration is complete

    • Unable to Migrate: Data migration is incomplete and Cisco IQ is unable to migrate the data

    If data is unable to migrate, you must manually migrate the data to the new Cisco IQ company account. See System Settings for more information about adding additional data to Cisco IQ.

  2. Once the migration process is complete, click Continue. You are redirected to the Cisco IQ Launchpad.

Logging In to Existing Accounts

Note: Customers with an existing Cisco IQ account who have not been added to a company account must contact the company’s Account Administrator to request access to the account.

To log in to an existing account:

  1. Navigate to Cisco IQ. The Cisco Log in page displays.

  2. Click Log in with SSO.

  3. Enter your CCO ID credentials into the Email field.

  4. Click Next.

  5. Enter your Password.

  6. Click Verify.

If you have one account, you are redirected to the Cisco IQ Launchpad.

If you have more than one account, you are redirected to the Welcome to Cisco IQ page.

Select Account Name
Select Account Name

Getting Started

Note: Before getting started, ensure you have fully onboarded to Cisco IQ. See Onboarding for more information.

Support Tiers

Cisco IQ Support Tier levels define the access and capabilities available to you within Cisco IQ and are designed to enhance your support and professional services experience. These levels are tied to your valid Cisco support contract and determine which features and tools you can utilize, from AI-driven insights and troubleshooting to asset and contract management. Understanding your level ensures you can fully leverage Cisco IQ’s capabilities while maintaining compliance with your contractual rights.

The following table outlines the Cisco IQ features available for each level.

Note: Capabilities are cumulative across support tier levels; higher levels include all capabilities from lower levels.

Basic Level Standard Level Signature Level
Know what you have Prioritize for operational resilience Accelerate operational excellence
Complete landscape clarity Track every Cisco asset and subcomponent with dynamic high-confidence data using the following features:
- Asset Inventory
- End-of-Life (EOL) Reports
- Service Coverage Reports
- Last Date of Support (LDOS) Dashboard
- Asset Tagging
Use the following features to analyze your network’s performance to determine where to allocate resources, helping you make informed decisions about infrastructure investments:
- EOL Insights¹
- Service Coverage Insights¹
- LDOS Insights¹
- Asset Criticality Insights¹
Proactive Resilience Gain visibility into important notifications that help you identify and address potential risks within your environment using the following features:
- Security Advisories Reports
- Field Notices Reports
Cisco IQ turns data into insights by correlating asset risks, allowing you to identify and prioritize the most critical security risks:
- Security Advisory Insights¹
- Security Hardening Insights¹
- Field Notice Insights¹
- Configuration Insights¹
The following features provide actionable recommendations to help improve security posture and optimize configurations within your environment:
- Configuration Deep Insights¹
- Configuration Recommendations¹
- Security Hardening Recommendations¹
Rapid resolution Manage your support cases and track resolution status in one location to resolve issues faster using the following features:
- Case Management
- Self-serve Troubleshooting¹
Receive AI-tailored diagnostics and root cause analysis using telemetry from devices connected through Cisco IQ Connector.

¹ Supports device and telemetry connection via Cisco IQ Link, Intersight, Meraki, SD-WAN Manager, and WebEx Control Hub.

Basic Capabilities

The Basic support tier provides foundational control through reliable and reactive support, including access to technical product support experts, self-serve troubleshooting, and centralized case management. To ensure full visibility, Cisco IQ unifies asset telemetry, contract information, and support history, providing a comprehensive view of your asset lifecycles, security advisories, and field notices. Additionally, you can strengthen your technical expertise by accessing foundational learning resources available through Cisco U.

The following table outlines the available capabilities for the Basic support tier.

Capability Description
Asset Inventory Asset Inventory provides an up-to-date list and rich visualizations for Hardware products, model and serial numbers, OS version, installed-at location, and service coverage details. It also provides a way to filter by ‘Last Signal’, which is when Cisco knew the asset was active based on Technical Assistance Center (TAC) Cases, contract renewal, telemetry, and so on.
End of Life EOL provides an up-to-date list and rich visualizations for Hardware and Software approaching, at, or having passed EOL milestones from End of Sales to LDOS, enabling lifecycle and technology refresh planning.
Service Coverage Service coverage reports provide an up-to-date list and rich visualizations for covered and uncovered assets.
LDOS Dashboard The LDOS Dashboard provides a centralized view of LDOS milestones, allowing for improved asset planning and budget forecasting before hardware or software reaches end-of-life, enabling operational risk reduction.
Asset Tagging Asset Tagging provides a way to organize inventory according to business needs by using Asset Tags, enabling the flexible organization of hardware and software assets by department, location, or project as key-value pairs.
Security Advisories Security advisories provide an automated solution that detects exposures, prioritizes vulnerabilities based on risk severity and criticality, and delivers executive-level insights to accelerate mitigation of critical threats, thereby enhancing enterprise resilience against evolving threats.
Field Notices Field Notices provide an automated solution that detects non-security related product issues, prioritizes issues based on impact severity and criticality, and delivers executive-level insights to accelerate resolution of critical operational concerns, thereby enhancing enterprise resilience and maintaining optimal performance.
Case Management Case Management provides an up-to-date list of Cisco TAC cases including case counts, status, severity, and Return Materials Authorizations (RMAs) associated with cases. It also provides the ability to open TAC cases (via cross-launch to Support Case Manager (SCM)) and rapidly update case information to facilitate resolution.
Self-serve Troubleshooting¹ Self-serve Troubleshooting provides a way to resolve issues instantly with the AI Assistant. This interactive tool provides real-time, context-aware troubleshooting and expert recommendations directly from Cisco’s verified knowledge base, allowing you to solve problems without the need to open a support case.

¹ Supports device and telemetry connection via Cisco IQ Link, Intersight, Meraki, SD-WAN Manager, and WebEx Control Hub.

Standard Capabilities

The Standard support tier enhances your operational efficiency by providing centralized triaging for solution-level issues and a dedicated case owner who coordinates with the necessary technical experts. You can proactively mitigate risks using AI-powered insights that correlate asset data with business criticality, offering clear visibility into your inventory, security, and configuration assessments. Additionally, you can align your team’s expertise with your specific business needs through personalized learning paths available in Cisco U.

The following table outlines available capabilities for the Standard support tier.

Capability Description
EOL Insights¹ EOL Insights provide intelligent querying, summarization, visualization, and reporting of EOL milestones to enable personalized prioritization of lifecycle and technology refresh planning.
Service Coverage Insights¹ Service Coverage Insights provide a visualization and analysis of service coverage details and renewal milestones, enabling personalized prioritization of coverage updates and renewal planning.
LDOS Insights¹ LDOS Insights provide a visualization and analysis of assets beyond or approaching their LDOS milestones, enabling personalized prioritization of lifecycle and technology refresh planning.
Asset Criticality Insights¹ Asset Criticality Insights enable the evaluation and identification of asset roles and their relative importance in your network for prioritization of risk mitigation efforts and improved operational resilience.
Security Advisory Insights¹ Security Advisory Insights provide intelligent querying, summarization, visualization, and reporting of assets affected by Security Advisories, enabling personalized prioritization of risk and security incident response.
Field Notice Insights¹ Field Notice Insights provide intelligent querying, summarization, visualization, and reporting of assets affected by Field Notices, enabling personalized prioritization of risk and response to known issues.
Security Hardening Insights¹ Security Hardening Insights provide an automated solution that assesses device configurations, identifies security hardening gaps based on impact severity and criticality, and delivers executive-level insights to accelerate implementation of critical hardening measures. It enhances enterprise resilience and reduces the attack surface against evolving threats while enabling the personalized prioritization of an improved security posture through intelligent querying, summarization, visualization, and reporting of assets at risk.
Configuration Insights¹ Configuration Insights provide an automated solution that assesses device configurations against Cisco-recommended best practices based on field-proven expertise. Intelligent querying, summarization, visualization, and reporting of affected assets enable personalized prioritization and accelerate remediation of critical configuration gaps, enhancing infrastructure resilience and reducing operational risk across the network.
Device-level Self-serve Troubleshooting Device-level Self-serve Troubleshooting with the AI Assistant provides tailored diagnostics and enables comprehensive root cause analysis beyond Self-serve Troubleshooting guidance through uploaded files.
Playbook for the AI ERA Enables rapid discovery and prioritized remediation of risks, enforces Zero Trust principles, and supports continuous autonomous defense with AI-powered insights and automation. It integrates expert guidance, automated workflows, and contextualized professional services to accelerate resilience and operational agility in the AI era.
IOS-XE Software Upgrade Automates the validation, deployment, and management of software upgrades for Cisco IOS-XE devices within the resilient infrastructure framework. It ensures devices remain compliant with Cisco-recommended best practices and security hardening standards, reducing operational risk and exposure to vulnerabilities.

¹ Supports device and telemetry connection via Cisco IQ Link, Intersight, Meraki, SD-WAN Manager, and WebEx Control Hub.

Signature Capabilities

The Signature support tier builds upon the Standard support tier to elevate your operational performance through defined restoration Service Level Agreements and access to a dedicated team of experts familiar with your unique environment. This tier focuses on preventing disruptions before they impact your operations by providing proactive security hardening, systematic root-cause elimination, and continuous expert-driven analysis of your assets. Additionally, you can utilize advanced Cisco U. certification training and virtual practice labs to build deep, technical proficiency.

The following table outlines available capabilities for the Signature support tier.

Capability Description
Configuration Recommendation¹ Configuration Recommendation provides actionable recommendations to address potential misconfigurations and inconsistencies.
Security Hardening Recommendations Security Hardening Recommendations provide an automated solution that delivers generic recommendations specific to each failed hardening check, addressing the underlying security issues clearly and concisely.
Executive Reports Executive Reports are automatically generated Periodic Service Review (PSR) reports. Each report provides a comprehensive view of support activity in your Cisco IQ account, consolidating data from multiple sources to surface case trends, key metrics, and actionable insights.

¹ Supports device and telemetry connection via Cisco IQ Link, Intersight, Meraki, SD-WAN Manager, and WebEx Control Hub.

Get Started Journey for Administrators

When logging in to your newly created or migrated Cisco IQ account for the first time, the Welcome page displays a Get Started journey. The Get Started journey differs depending on whether the account was created with or without migrated data.

Note: The Get Started journey experience varies based on Role-Based Access Control (RBAC) permissions.

New Account via Creation

The Get Started journey for newly created accounts guides you through the initial onboarding steps required to configure your Cisco IQ environment and explore Cisco IQ.

Connecting Cisco Cloud Products

Note: You must connect at least one (1) cloud product for this step to be complete.

Connecting your Cisco cloud product data to Cisco IQ is the fastest way to start using its powerful, personalized features. You can receive tailored insights in minutes after setting up your data connections.

To connect your Cisco cloud products, see Data Connectors.

Adding Service Contracts

Note: You must add at least one (1) service contract for this step to be complete.

Adding contracts unites data from contracts associated with different team members and incorporates assets not connected to your inventory via telemetry, enabling centralized support coverage visibility and preventing renewal surprises.

To add your service contracts, see Service Contracts.

Note: You must register at least one (1) Cisco IQ Link for this step to be complete.

To establish communication with your on-premises devices, you must configure Cisco IQ Link. Cisco IQ Link brings all the power of Cisco IQ to your on-premises devices not already managed by a Cisco cloud platform. Cisco IQ Link can be installed as a Virtual Machine (VM) in your data center and linked to your Cisco IQ account.

To connect your on-prem devices, see Adding Cisco IQ Link Instances.

Managing User Access

Note: You must add at least two (2) users for this step to be complete.

Cisco IQ’s simple access control features are designed for both small teams and large organizations. You can add users and assign administrator or view-only roles to groups and individuals.

To add users and assign permissions, see Users.

Exploring Cisco IQ

The final step of your Get Started journey is to explore Cisco IQ’s features and modules that are available to you, including:

  • Launchpad: Access modules, discover new features, and create dashboards

  • Assets Module: See Assets Module for more details

  • Assessments Module: See Assessments Module for more details

  • Support Module: See Support Module for more details

  • AI Assistant: See AI Assistant for more details

  • System Settings: Manage your account settings, grant users access, configure data connections, and view activity and logs for your account; see System Settings for more details

New Account via Migration

If your new Cisco IQ account was created via migration, information from your previous account is already available. As a result, the Get Started journey for newly migrated accounts is limited to reviewing the migration, detailed below.

Reviewing Migration

To review the migration:

  • Verify your contracts migrated successfully in Home > System Settings > Service Contracts

  • Validate all required data connections are properly configured in Home > System Settings > Data Connectors

  • Verify user data migrated successfully and grant access to migrated users by activating their accounts in Home > System Settings > Identity & Access > Users

  • Verify your assets migrated successfully in Home > Assets > Inventory

Get Started Journey for General Users

When logging in to your Cisco IQ account for the first time, the Welcome page displays a Get Started journey. This journey guides you through Cisco IQ features and common workflows.

Note: The Get Started journey experience varies based on RBAC permissions.

Exploring Cisco IQ

Explore Cisco IQ’s features and modules that are available to you, including:

Generating Your First AI Report

Cisco IQ’s AI-powered Analyze feature generates customizable, targeted reports based on selected assets which can be tailored to your specific business needs.

See Assets Module for more information on generating your first AI report.

Asking the AI Assistant a Question

The final step of your Get Started journey is to launch the AI Assistant from anywhere and ask a question about your assets, cases, or assessments.

See AI Assistant for more information on using the AI Assistant.

Dashboards

The Dashboards tab provides a view of the following available dashboards in Cisco IQ.

LDOS Dashboard

The LDOS dashboard provides comprehensive, detailed insights into LDOS metrics, enabling customer visibility, empowering you to proactively manage risks, and supporting more efficient and informed decision-making.

LDOS Dashboard
LDOS Dashboard

Filtering Views for LDOS Dashboard

You can filter the dashboard view by choosing a filter from the drop-down lists or click Filters and choose from the list of available filter options.

Note: Some filters may be hidden depending on screen zoom settings.
Different filters are available depending on your roles and permissions.

Viewing Details for LDOS Dashboard

When clicking Open in Assets, the page redirects to the Inventory page. See Inventory for more details.

Peer Benchmarks Dashboard

The Peer Benchmarks dashboard provides contextual insights into how your environment performs relative to other Cisco IQ customers. By comparing your key metrics against peer organizations, you can identify gaps, gauge performance, and take targeted action to improve your infrastructure’s health and support posture.

Note: Peer Benchmarking is available on Cisco IQ SaaS only.

The dashboard displays the following information:

  • Connected to telemetry: The percentage of assets in your inventory with telemetry enabled, compared to peers

  • Last Date of Support snapshot: The percentage of your assets that have reached or are approaching their Last Date of Support milestone, compared to the peer average

  • LDOS assets vulnerable to Security Advisories: The percentage of assets that are both past LDOS and affected by active security advisories

Peer Benchmarks Dashboard
Peer Benchmarks Dashboard

Filtering Views for Peer Benchmarks Dashboard

You can filter the dashboard view by choosing a filter from the drop-down lists or click Filters and choose from the list of available filter options.

Note: Some filters may be hidden depending on screen zoom settings.
Different filters are available depending on your roles and permissions.

Benchmarking Insights and Recommendations

The Benchmarking dashboard surfaces three types of contextual insights based on your peer comparison:

  • Contextual insights: View the average or mean performance of your peer group and see how you measure up across key metrics.

  • Gap analysis: Identify areas where your environment lags behind peers, and track improvement over time as you make changes.

  • Goals and strategic planning: Discover technologies or processes that top-performing peers have successfully adopted — such as AI-powered self-troubleshooting — and receive recommendations to implement similar improvements.

Actionable recommendations are displayed exclusively when a meaningful gap exists between your performance and your peer group. Best practice suggestions from top-performing peers are presented alongside the gap data to guide remediation.

Note: Peer Benchmark data is anonymized and aggregated.

Resilient Infrastructure Service

The Resilient Infrastructure Service page provides a guided, step-by-step playbook to help you protect your infrastructure from emerging threats. It combines asset visibility, security advisory insights, and automated software upgrade capabilities into a unified workflow.

Note: Resilient Infrastructure Service capabilities require Standard or Signature support tier assets. See Support Tiers for more information.

Accessing Resilient Infrastructure Service

To navigate to the Resilient Infrastructure Service tab:

Resilient Infrastructure Playbook
Resilient Infrastructure
Playbook
  1. From the Cisco IQ Home page, click Resilient Infrastructure Service. The Resilient Infrastructure Playbook for the AI Era page displays.

  2. Complete the steps outlined below to protect your infrastructure from emerging threats.

Step 1: Map the Attack Surface

The Map the Attack Surface step provides a comprehensive view of whether telemetry is enabled for all Standard and Signature tier assets in your network.

Map the Attack Surface
Map the Attack Surface

The step displays:

  • Total Asset Count: The number of Standard and Signature tier assets in your network

  • Pie Chart: Displays the percentage of assets with or without telemetry coverage

  • Insights: Identifies coverage gaps, such as assets with limited or no telemetry visibility

To drill down into your asset inventory with relevant filters applied, click Open in Assets.

Step 2: Remediate Critical Exposures

The Remediate Critical Exposures step surfaces certain active security advisories affecting your assets and helps you prioritize remediation.

IOS-XE Software Upgrade Workflow
IOS-XE Software Upgrade
Workflow

The step displays:

  • Critical Advisories Count: Identified number of critical software hardening advisories affecting your environment

  • Assets Affected: The number of assets impacted by the identified advisories

  • Insight: An analysis of which advisories can be resolved through a software upgrade (for example, “An IOS-XE software version upgrade resolves the advisories on 70 affected assets.”); see Software Upgrade for more information

To view the full list of affected assets filtered by security advisories, click Open in Assets.

Step 3: Modernize Legacy Systems

The Modernize Legacy Systems step provides visibility into legacy assets approaching or past their LDOS milestones.

Modernize Legacy Systems
Modernize Legacy Systems

To view your inventory filtered by assets with active LDOS milestones, click Open in LDOS Dashboard.

Expert Support for Your Infrastructure Resilience

Cisco and its partner ecosystem provide the expertise needed to plan, execute, and maintain your infrastructure. Whether you are addressing OS upgrades, network refreshes, or implementing Zero Trust principles, Cisco is here to reduce your operational risk.

Expert Support
Expert Support

To request a consultation, click Request consultation. A Cisco team member will reach out via email at the address associated with your CCO account.

Software Upgrade

The Software Upgrade workflow is accessible directly from the Resilient Infrastructure Playbook when AI Insights identify assets where a software upgrade resolves active security advisories. The workflow guides you through four sequential stages: Plan, Prepare, Execute, and Verify.

Note: The Software Upgrade workflow is available for IOS-XE assets only.

IOS-XE Software Upgrade Workflow
IOS-XE Software Upgrade
Workflow

Stage 1: Plan

The Plan stage confirms your upgrade target version and change window before proceeding.

Plan Stage
Plan Stage
  1. Review the following upgrade details to confirm the target version is appropriate for your environment:

    • Asset: The device to be upgraded

    • Current Version: The currently installed IOS-XE version

    • First Fixed Version: The minimum IOS-XE version that resolves the identified advisory

    • Related Advisory: The security advisory driving this upgrade

  2. To confirm the platform and version compatibility, run the following CLI commands on the device:

    show version     ! current platform + version
    show platform    ! hardware/supervisor model
  3. Check the check box to confirm the first fixed IOS-XE version is acceptable as the target version for upgrade.

  4. Schedule a maintenance window with stakeholders and document the start and end times in your change system.

  5. Notify dependent service owners of the expected outage.

  6. Ensure a console path (out-of-band or physical) exists.

  7. Check the check box to confirm.

  8. Click Next to proceed to the Prepare stage.

Stage 2: Prepare

The Prepare stage verifies device readiness and captures a pre-upgrade baseline before executing the upgrade.

Prepare Stage
Prepare Stage
  1. Verify Console Access and Configuration Backup using the following steps:

    1. Connect to the console (directly or via console server) and confirm access.

    2. Capture the running configuration using the following command:

      show running-config
    3. Save the configuration to your approved backup store (SFTP, SCP, archive or enterprise backup tool).

  2. Optionally, verify backup integrity. Check the check box to confirm.

  3. Confirm asset readiness using the following steps:

    1. Confirm reachability to the image or transfer server using the following command:

      ! Confirm you can reach the image/transfer server
      ping <transfer-server-ip>
      
      ! If using name server
      show hosts
      ping <server-fqdn>
    2. Check the flash or disk against the target image size using the following command:

      dir flash: | include bytes total
      
      ! Compute free space vs. image size (+ add-ons). Need image size plus headroom
      show install summary ! list installed packages (install mode)
      show flash:
      
      ! Install mode: remove inactive/old installed images safely
      install remove inactive ! prompts to remove unused install files
      
      ! Bundle mode / leftover files: delete old images explicitly
      delete flash:<old-image>.bin
      
      ! On stacks, repeat per member: delete flash-1: flash-2: ...
    3. Configure the register check and ensure the device auto-boots the new image after reload using the following command:

      show version | include register
      
      ! Must be 0x2102 (auto-boot using system list). If 0x2142 or other:
      configure terminal
      config-register 0x2102
      end
    4. Validate RSA, Transport Layer Security, and cryptography readiness using the following command:

      show crypto key mypubkey rsa ! an RSA key/cert should exist
      show ip domain-name
      show running-config | include domain-name
      show snmp user ! look for MD5 auth / DES priv
      
      ! Remediate to SHA + AES before upgrading to 17.14.1+
      configure terminal
      no snmp-server user <user> <group> v3 auth md5 ...
      snmp-server user <user> <group> v3 auth sha <pass> priv aes 128 <pass>
      end
    5. Confirm the IP domain name is configured using the following command:

      Note: Required for cryptography or certificate operations.

      show running-config | include ip domain
      
      ! If missing:
      configure terminal
      ip domain name example.com
      end
    6. Confirm the startup configuration is present to prevent configuration loss on reboot using the following command:

      show startup-config | include !
      
      ! Confirm a startup-config is present
      
      ! Ensure running == startup before reboot:
      write memory
      show running-config | redirect flash:pre-upgrade-running.cfg ! archive copy on flash
    7. Confirm license and support tier supports target image features using the following command:

      show license summary
      show license status
      show license usage
      
      ! Confirm the device is in the right support tier for the new image's features
    8. Confirm the target image matches the platform or supervisor minimum supported version using the following command:

      show version ! current platform + version
      show platform ! hardware/supervisor model
      
      ! Confirm the chosen image matches this exact platform/supervisor and
      ! the target version >= the minimum supported for your role/features
    9. Validate stack before upgrading using the following command:

      Note: All stack members must be ready and on the same image (Catalyst 9000 stacks only).

      show switch
      show switch stack-ports
      
      ! All members must be Ready and running the same image
  4. Do not proceed until all checks pass. If you cannot remediate an item, open a TAC case before proceeding. Check the check box to confirm all readiness checks have passed or have been remediated.

  5. Pre-upgrade collection using the following steps:

    1. Run pre-change show commands, snapshots, or monitoring to capture what your organization requires (topology snapshots, routing neighbors, interface counters, NMS baselines, and similar).

    2. Store all outputs with a timestamp and asset identifier alongside your change record.

    3. Check the check box to confirm pre-check collection is complete.

  6. Stage the IOS-XE Image using the following steps:

    1. Download the target IOS-XE install-mode package for your platform from your approved mirror or Cisco Software Download.

    2. Transfer the image to the device’s flash storage using SCP, TFTP, USB, or your preferred method:

      dir bootflash:
    3. Verify the file size on the device matches the downloaded package.

    4. Check the check box to confirm the image is staged and ready to execute.

  7. Capture baseline operational state for post-upgrade comparison using the following steps:

    1. Run a version and install summary check:

      show version
      show install summary
    2. Capture the interface state:

      show ip interface brief
    3. Run routing or service checks relevant to this asset (for example, show ip route summary, show ip bgp summary).

    4. Save all outputs with timestamps and asset identifiers alongside your change record.

    5. Check the check box to confirm the pre-upgrade baseline is captured.

  8. Click Next to proceed to the Execute stage.

Stage 3: Execute

The Execute stage allows you to run the IOS-XE upgrade using either a manual or automated method.

Execute Stage
Execute Stage

Choose the upgrade method appropriate for your environment:

  • Manual upgrade: You run the install command and monitor the reload

  • Automated upgrade: Cisco IQ performs pre-flight checks, install, and monitoring; requires service-impact acknowledgement

Note: The upgrade method cannot be changed once the automated upgrade has started.

Manual Upgrade

To run a manual upgrade:

Manual Upgrade
Manual Upgrade
  1. Confirm you are within your maintenance window and the image is on flash:

    show install summary
    dir bootflash:
  2. Run the one-step install:

    install add file bootflash:<package-name> activate commit
  3. Allow the device to reload and confirm reachability.

  4. Check the check box to confirm the upgrade is installed and the asset is reachable.

Automated Upgrade

Warning: This process interrupts active traffic through the asset. The asset reloads during installation and interrupts active sessions and traffic until the installation is complete.

To run an automated upgrade:

Run Automated Upgrade
Run Automated Upgrade
  1. Ensure you are within your maintenance window before starting.

  2. Click Next.

  3. Review and acknowledge the service impact notice.

  4. Click Start automated upgrade.

Cisco IQ performs the following steps automatically and displays progress in real time:

  • Running pre-flight checks: Validates that the device is ready for upgrade

  • Installing software: Installs the staged IOS-XE image

  • Monitoring reload: Monitors the device through reload and confirms reachability

A status message “Upgrading to IOS-XE [target version]…” displays the target version.

Note: This process may take a few minutes. You can close the page and return later to check on progress.

Note: Upon completion of an automated upgrade, a success notification displays that must be dismissed before continuing.

Stage 4: Verify

The Verify stage confirms that the upgrade was successful and documents the outcome in your change record.

Note: If you encounter issues during verification, refer to the Recovery procedure.

  1. Run the version and check on the asset using the following command:

    show version
    show install summary
  2. Compare the reported version to the target version.

  3. Confirm that the active install package matches the intended upgrade.

  4. Check the interface and link state using the following command:

    show ip interface brief
  5. Check the routing and neighbor status relevant to this asset (for example, show ip route summary, show ip ospf neighbor, show ip bgp summary).

  6. Perform service-specific validation according to your runbook (latency, application probes, monitoring alerts).

  7. Compare the results to the captured baseline.

  8. Document any issues in your change record.

  9. Confirm and choose the radio button of the outcome that reflects the result of the upgrade:

    • Successful: The asset is running the target version and services are verified

      Note: If code must be rolled back after an upgrade, the upgrade must be marked as unsuccessful.

    • Unsuccessful: The upgrade did not complete as expected

      Note: If the upgrade was Unsuccessful, expand the Recovery procedure section for remediation guidance.

  10. Click Done to complete the Software Upgrade workflow.

Cisco Support Tiers

The Cisco Support Tiers page provides an overview of what features are available for the purchased support tier and the number of Assets related to linked support contracts, enabling you to easily understand included support capabilities and take action to manage and review them. See Support Tiers for more detailed information about support tier features.

Cisco Support Tiers
Cisco Support Tiers

Reports

The Reports page provides a centralized location to save and manage your AI-generated analysis reports and access automatically generated executive reports. The page includes two tabs:

  • Your Reports: View, manage, and customize AI-generated analysis reports captured from various entry points, including the AI Assistant, inline messages, and Full Analysis views across Cisco IQ. Key capabilities include:

    • Snapshot Management: Efficiently browse report history and switch between snapshots

    • Export and Cleanup: Download reports as PDFs or manage your library by deleting reports individually or in bulk

Reports
Reports
  • Executive Reports (Account Administrators only): View and download automatically generated Growth and PSR reports as PDFs. Each report provides a comprehensive view of support activity across the contracts in your Cisco IQ account, consolidating data from multiple sources to surface case trends, key metrics, and actionable insights. Available for Signature Level customers only.

Note: Snapshots are a specific version or iteration of a report. You can maintain multiple snapshots under a single report, allowing you to track data over time — such as updated dates or adjusted parameters — without creating redundant files.

Obtaining Reports

Generating Reports from the AI Assistant

To generate a report from the AI Assistant:

  1. Click the AI Assistant icon.

    AI Assistant
    AI Assistant
  2. Select a prompt or enter a question. Wait for a response to generate.

Note: The prompt or question must generate analysis data. For example, the “Summarize assets past Last Date of Support (LDOS)” prompt produces an Analyze response option.

Analyze Response
Analyze Response
  1. Click Analyze response. The AI Assistant generates an analysis.

    Saving the Report
    Saving the Report
  2. Click Save. The Save report window opens.

    Report Details
    Report Details
  3. Enter a Report name.

  4. Optionally, enter a Description.

  5. Click Save. A confirmation message displays.

  6. To view the report, click the View Report link in the confirmation message, or navigate to Your Reports from the Home page.

Generating Reports from Insights

To generate a report:

  1. Navigate to a page with Insights Analysis (for example, Assets > Inventory or Assessments > Security Advisories).

    Insights Analysis
    Insights Analysis
  2. Wait for the Insights to generate. Expand the Insights widget and click Full Analysis.

  3. Click Save. The Save report window opens.

    Report Details
    Report Details
  4. Enter a Report name.

  5. Optionally, enter a Description.

  6. Click Save. A confirmation message displays.

  7. To view the report, click the View Report link in the confirmation message, or navigate to Your Reports from the Home page.

Customizing Reports

The Customization feature enables you to tailor AI-generated analysis reports to your specific needs directly from a report view.

To customize a report:

  1. Initiate an AI-generated analysis from the AI Assistant or Insights. See Obtaining Reports for more information.

    Customize
    Customize
  2. Click Customize.

    Report Customization
    Report Customization
  3. Customize the report using the following capabilities:

    • Reordering widgets: Drag and drop charts, tables, and insights to rearrange the report layout

    • Removing widgets: Exclude specific charts, tables, or insights

    • AI-assisted editing: Use natural language prompts to request specific modifications to titles, descriptions, and key insights

    • Suggested prompts: Leverage a library of categorized, AI-generated suggestions to guide your customizations

  4. Click Keep to save your changes.

Regenerating Reports

When regenerating an initial report, a new version of the report is created, referred to as a Snapshot.

To regenerate a report:

  1. Navigate to the Reports > Your Reports page.

  2. Click the desired report.

  3. Click Regenerate.

Report Versioning

Delete Snapshot
Delete Snapshot

After regenerating an initial report, you can view snapshots and previous versions of the report by selecting the date and time drop-down field in the Report view.

Viewing Executive Reports

Note: Executive reports are only available for Signature Level customers.

Executive reports can be viewed from the Executive Reports tab.

To view executive reports:

  1. From the Reports page, click the Executive Reports tab.

  2. Click the Name of the desired report to view report details.

PSR Report Details

PSR Reports include the following information:

  • Executive Summary: Key insights and call-outs across all reporting pillars

  • Case Key Performance Indicators (KPIs): Case performance metrics for both cases and RMA analysis

  • Software Maintenance Window (SMW) Analysis: SMW usage data for the reporting period (entitled accounts only)

  • Service Level Agreement (SLA) Analysis: SLA performance data (entitled accounts only)

Deleting Reports

To delete a report from the Your Reports page:

  1. Navigate to the Your Reports tab.

  2. In the row of the report, choose the More Options icon > Remove.

  3. Click Delete report.

Deleting Specific Report Versions

To delete a specific report version:

  1. Navigate to the Your Reports tab.

  2. Click the Report.

  3. Select the report version from the date and time drop-down field.

    Delete Snapshot
    Delete Snapshot
  4. Click Delete snapshot.

    Delete Report
    Delete Report
  5. Click Delete report to confirm.

System Settings

To navigate to the System Settings menu, choose Home > System Settings. The Account Details page displays.

Note: System Settings are only available to Account Administrators.

Account Details

The System Settings feature facilitates easy management, access control, and data allocation, ensuring comprehensive visibility and access for Account Administrators. When viewing the Account Details page, the Details section displays the following information:

  • Account name

  • Account type

  • Data storage region

  • Users

  • Create date

  • Account admins

  • Account ID

  • Last login date

Editing the Account Name

Only the Account name can be changed from the Account Details page.

Note: To change fields, such as Data storage region, a new company account must be created.

To edit an account name:

Account Details
Account Details
  1. Click Edit.

    Edit Account Name
    Edit Account Name
  2. Revise the Account Name.

  3. Click Save.

Users

User accounts are created, modified, and deleted on the Users page. To navigate to the Users page, choose System Settings > Identity & Access > Users. The Users page displays.

Add User
Add User

You can Search and Filter to narrow the list by using the fields at the top of the page.

Adding New Users

Note: Only Account Administrators or other authorized users can add new users.

To add a new user:

  1. From the Users page, click Add User. The Add User page displays.

    Add User
    Add User
  2. Choose the User radio button.

  3. Enter an Email address.

  4. Optionally, choose the user group(s) from the Select user groups drop-down list.

  5. Choose the Role from the drop-down list.

Note: Users must belong to at least one user group with a role or be assigned at least one role.

  1. Confirm that the Send invitation email check box is checked.

  2. Click Save. A confirmation displays on the Users page.

Users receive an email after being invited by an Account Administrator.

Email Invitation
Email Invitation

Invited users can click Log In from the email to log in to their account. After logging in, the user’s status becomes Active.

Editing User Access

To edit the user groups, role, or resource groups of a user account:

Edit Access
Edit Access
  1. From a desired user on the Users page, choose the More Options icon > Edit access. The Edit User Details page displays.

    Edit User Details
    Edit User Details
  2. Edit the desired user groups, role, and resource groups.

Note: Resource groups only display for select roles.

  1. Click Save.

Sending Invitation Emails

To send an invitation email to an existing user account:

  1. Navigate to the Users page.

  2. From a desired user, choose the More Options icon > Send invitation email. A confirmation displays.

Activating Users

To activate a user account:

  1. From a desired user on the Users page, choose the More Options icon > Activate user. The Activate user window opens.

    Activate User Confirmation
    Activate User Confirmation
  2. Optionally, check the Resend invitation emails for activated users check box.

  3. Click Activate user to confirm. A confirmation displays.

Deactivating Users

To deactivate a user account:

  1. From a desired user on the Users page, choose the More Options icon > Deactivate user. The Deactivate user window opens.

    Deactivate User Confirmation
    Deactivate User Confirmation
  2. Click Deactivate user to confirm. A confirmation displays.

Deleting Users

Warning: Deleting users cannot be reversed.

To delete a user:

  1. From a desired user on the Users page, choose the More Options icon > Delete. The Delete user window opens.

    Delete User Confirmation
    Delete User Confirmation
  2. Click Delete user. The user is deleted.

Resource Groups

Resource groups are dynamic collections that specify resources based on their type and attributes. Configuring resource groups enables you to restrict data access of a role to the resources that meet the conditions of the group. Resources can belong to multiple resource groups. As an Account Administrator, you can create, edit, and delete resource groups.

To view resource groups:

  1. Choose System Settings > Identity & Access > Resource Groups. The Resource Groups page displays.

    Resource Groups
    Resource Groups
  2. Use the Search field to narrow the list.

  3. Click a resource group name to display its details.

Resource Group Details
Resource Group Details

Creating Resource Groups

To create a new resource group:

  1. From the Resource Groups page, click Create resource group. The Create Resource Group page displays.

    Create Resource Group
    Create Resource Group
  2. Enter a Name for the resource group.

  3. Optionally, enter a Description.

  4. Click Manage assets. The Manage assets window opens.

    Manage Assets
    Manage Assets
  5. Check the check box of the desired assets.

  6. Click Apply.

  7. Click Save.

Editing Resource Groups

To edit a resource group:

Edit
Edit
  1. From a record on the Resource Groups page, choose the More Options icon > Edit. The Edit Resource Group page displays.

    Edit Resource Group
    Edit Resource Group
  2. Edit the resource group attributes, as desired.

  3. Click Save.

Deleting Resource Groups

Warning: Deleting resource groups cannot be reversed.

To delete a resource group:

  1. From a record on the Resource Groups page, choose the More Options icon > Delete. The Delete resource group window opens.

    Delete Resource Group Confirmation
    Delete Resource Group
    Confirmation
  2. Click Delete resource group. The resource group is deleted.

User Groups

User groups enable you to control users effectively across the account by creating, editing, and deleting user groups.

Note: The All account users user group exists by default on all accounts in Cisco IQ and cannot be deleted or edited. It always includes all account users of any specific type. Its purpose is to apply roles to all users on the account.

To view user groups:

  1. Choose System Settings > Identity & Access > User Groups. The User Groups page displays.

    User Groups
    User Groups
  2. Use the Search field to narrow the list.

  3. Click a user group name to display its details.

User Group Details
User Group Details

Creating User Groups

To create a new user group:

  1. Click Create User Group. The Create user group page displays.

    Create User Group
    Create User Group
  2. Enter a Name for the user group.

  3. Optionally, enter a Description.

  4. Click Manage users. The Manage users window opens.

    Manage Users
    Manage Users
  5. Check the check boxes of the desired users.

  6. Click Apply.

  7. Choose a Role from the drop-down list.

  8. Optionally, choose a Resource group from the drop-down list.

Note: Adding resource groups limits the resources the user group has access to. If a role is assigned but no resource groups are selected, the role is applied to all resources relevant to the role in the account.

  1. Click Save. The new user group displays in the User Groups table.

Editing User Groups

To edit a user group:

Edit
Edit
  1. From a record on the User Groups page, choose the More Options icon > Edit. The Edit user group page displays.

    Edit User Group
    Edit User Group
  2. Edit the user group attributes as desired.

  3. Click Save.

Deleting User Groups

Warning: Deleting user groups cannot be reversed.

To delete a user group:

  1. From a record on the User Groups page, choose the More Options icon > Delete. The Delete user group window opens.

    Delete User Group Confirmation
    Delete User Group
    Confirmation
  2. Click Delete user groups. The user group is deleted.

Partners

Adding partners to your Cisco IQ account enhances the collaboration between you, your partners, and Cisco. Your partners can help you optimize your assets, manage your environment, and maintain the security and health of your organization’s network. Partners can only view products and services they have sold you.

As an Account Administrator, you can invite partners to access your Cisco IQ account and control their level of access. The list of available partners is retrieved from Partner Self-Service (PSS). Partners must be registered in PSS for the Cisco IQ application to display in the list. Additionally, only partners associated with the contracts added to your Cisco IQ account are included.

Note: The Partners feature in System Settings is only available for a limited number of partners who are participating in the Early Field Trial program.

To view the partners with access to your Cisco IQ account:

  1. Choose System Settings > Identity & Access > Partners. The Partners page displays.

    Partners
    Partners
  2. Use the Search field to narrow the list.

  3. Click a Partner name to display its details. The following details display:

    • Partner Name: The name of the Partner

    • Added: The date the Partner was added

    • Roles: Displays roles that are assigned in the Partner account

    • Partner Users: Displays a list of users assigned to each role

Partner Details
Partner Details

Adding Partners

To invite partners to your Cisco IQ account:

  1. From the Partners page, click Add partner. The Add Partner page displays.

    Add Partner
    Add Partner
  2. Choose partners from the list to add them to your account.

  3. Check Share administrator contact information if you wish to allow partners to view the name and email address of all Account Administrators.

  4. Click Add partner(s). The Grant login access? window opens.

    Grant Login Access
    Grant Login Access
  5. Check the I agree to above terms and conditions of access check box, and click Grant login access.

Editing Sharing Preferences

To edit the ability of partners to view the name and email address of your Account Administrators:

  1. From a record on the Partners page, choose the More Options icon > Manage sharing preferences. The Manage sharing preferences window displays.

    Manage Sharing Preferences
    Manage Sharing Preferences
  2. Check or uncheck the Share administrator contact information check box, as desired.

  3. Click Save.

Removing Partners

To remove a partner from your Cisco IQ account:

  1. From a record on the Partners page, choose the More Options icon > Revoke access. The Remove partner window opens.

    Revoke access
    Revoke access
  2. Click Remove partner. The partner is removed from your Cisco IQ account.

Tags

Asset tags are custom labels you assign to inventory assets in Cisco IQ. A tag is a key:value pair — for example, Environment:Prod or Label:Campus — that you define. Account Administrators can create and delete tags and can assign users to a resource group, enabling them to assign asset tags to a device. See Resource Groups for more information about assigning users to a resource group.

Creating Asset Tags

To create a tag:

  1. Choose Home > System Settings > Tags. The Tags page displays.

    Tags
    Tags
  2. Click Create tag. The Create tag page displays.

    Create Tag
    Create Tag
  3. Enter the tag value in the Enter key:value field.

Note: Tags names are in key:value format (for example, City:NYC).

  1. Click Create. The new tag displays in the tag list on the Tags page.

Deleting Asset Tags

To delete a tag:

  1. Choose Home > System Settings > Tags. The Tags page displays.

    Tags
    Tags
  2. Check the check box(es) of the tag(s) to delete.

  3. Click Delete tags. A confirmation displays.

    Delete Tag Confirmation
    Delete Tag Confirmation
  4. Click Delete to confirm.

Data Connectors

Cisco IQ uses data connectors as part of a multi-layered data ingestion approach to provide comprehensive network insights. Data Connectors gather telemetry from assets on your network, enabling Cisco IQ to deliver relevant insights and trusted expertise.

Adding Cloud Connectors

Connecting your Cisco cloud product data to Cisco IQ is the fastest way to start using its powerful, personalized features. You can receive tailored insights in minutes after setting up your data connections to the following product controllers: Intersight®, Meraki Dashboard, SD-WAN Manager, Webex® Control Hub.

To connect your Cisco cloud products:

  1. Choose System Settings > Data Connectors. The Data Connectors page displays.

    Unlink Legacy Collector
    Unlink Legacy Collector
  2. Click Connect for the desired cloud connector.

  3. Complete the following steps for the selected cloud connector:

    Intersight

    1. Check the check box(es) of the desired account(s).

    2. Click Connect accounts. You are redirected to the Data Connectors page and a confirmation displays.

    Webex

    Edit Maintenance Window
    Edit Maintenance Window
    1. Click Open case from the Add Webex Organization window. You are redirected to SCM.

    2. Create a support case in SCM.

    Catalyst SD-WAN Manager

    1. Check the check box(es) of the desired organization(s).

    2. Click Connect organizations. You are redirected to the Data Connectors page and a confirmation displays.

    Meraki

    Connect Meraki
    Connect Meraki
    1. Follow the on-screen instructions.

    2. Enter the API Key.

    3. Click Connect. You are redirected to the Data Connectors page and a confirmation displays.

Cisco IQ Link is an on-premises component of Cisco IQ designed to provide you with richer and more intelligent insights, such as hardware and software lifecycle and inventory reports. It consolidates previous collectors into a single connector that you install on a VM to gather detailed telemetry data from your devices.

Cisco IQ Link is deployed within your on-premises network to perform automated device discovery and telemetry collection. Cisco IQ Link supports the direct connection and integration with Catalyst Center. In addition, if your account was created via migration, you can leverage your CX Agent or CSPC to connect telemetry.

Note: There is no limit to the number of Cisco IQ Link instances that can be deployed and connected for each customer account in Cisco IQ; however, each instance of Cisco IQ Link can connect to up to 20 Catalyst Centers (non-cluster).

Note: For cloud-managed controllers, Cisco IQ Link is not required, as the necessary data can be accessed directly via Cisco Cloud.

Note: When performing or assisting Cisco IQ Link setup, you must ensure you have VPN access where required to successfully cross-launch Cisco IQ Link. This ensures proper connectivity and functionality when accessing Cisco IQ Link remotely via the Cisco IQ.

To add Cisco IQ Link instances in Cisco IQ:

  1. Navigate to the Data Connectors page.

    Unlink Legacy Collector
    Unlink Legacy Collector
  2. Click Add Cisco IQ Link.

    Download the OVA or VHD
    Download the OVA or VHD
  3. Download the Open Virtual Appliance (OVA) or Virtual Hard Disk (VHD):

  4. Choose the Hypervisor from the drop-down list.

  5. Choose the Version from the drop-down list.

  6. Click Download.

  7. Click Review the full documentation to access the Cisco IQ Link Getting Started Guide.

To edit a Cisco IQ Link instance name:

  1. Navigate to the desired Cisco IQ Link instance on the Data Connectors page.

    Accelerated Support Access Option
    Accelerated Support Access
    Option
  2. Choose the More Options icon > Edit name.

  3. Edit the name as desired.

  4. Click Update.

Removing Connected Accounts from Cloud Connectors

To remove a connected account from your cloud connector, you must open a support case.

To open a support case:

  1. Navigate to the desired cloud connector on the Data Connectors page.

    Unlink Legacy Collector
    Unlink Legacy Collector
  2. Click the Settings icon. The Connected accounts window opens.

    Remove Cloud Connector Connected Account
    Remove Cloud Connector Connected
    Account
  3. From the desired account, choose the More Options icon > Remove.

  4. Click Open case to open a support case.

To remove a Cisco IQ Link instance from your data connectors:

  1. Navigate to the desired Cisco IQ Link instance on the Data Connectors page.

    Accelerated Support Access Option
    Accelerated Support Access
    Option
  2. Choose the More Options icon > Remove Cisco IQ Link. A confirmation displays.

  3. Click Remove to confirm.

Removing Legacy Collectors

Note: Legacy collectors only display in accounts that were migrated from CX Cloud.

To remove a connected legacy connector:

  1. Navigate to the desired legacy collector on the Data Connectors page.

    Unlink Legacy Collector
    Unlink Legacy Collector
  2. Choose the More Options icon > Remove. A confirmation displays.

  3. Click Open case to open a support case to remove the legacy collector.

Account Administrators can configure automatic upgrade schedules for Cisco IQ Link on-premises instances directly from Cisco IQ. This ensures your Cisco IQ Link instances stay current with the latest software versions, patches, and metadata without requiring manual intervention.

Note: Only Account Administrators can configure upgrade schedules. This feature applies to Cisco IQ Link on-premises instances that have already been registered to your Cisco IQ account. See Adding Cisco IQ Link Instances for more information.

Editing the Maintenance Window

To access the upgrade schedule settings for a Cisco IQ Link instance:

  1. From the Cisco IQ Home page, choose System Settings > Data Connectors > Cisco IQ Link.

  2. Navigate to the relevant Cisco IQ Link instance.

  3. Choose the More Options icon > Edit maintenance. The Edit maintenance window opens.

    Edit Maintenance Window
    Edit Maintenance Window
  4. Edit the Day field.

  5. Edit the Time field.

  6. Click Save. The maintenance window is updated.

Editing the Upgrade Schedule

To edit an automatic upgrade schedule:

  1. Navigate to the relevant Cisco IQ Link instance.

  2. Choose the More Options icon > Edit update schedule.

    Remove Service Contract Confirmation
    Remove Service Contract
    Confirmation
  3. Choose one of the following options:

    • Update now: Configure the update to start immediately

    • Update later: Choose a date and time to start the update

  4. Click Save.

Accelerated Support Access

Accelerated Support Access is enabled through the following settings:

  • Cisco IQ Link Rapid Resolution: Automates data collection and diagnostics when a case is opened and allows AI Assistant access through IQ Link for show commands and data collection only; it does not make device changes or use customer data for AI model training

  • TAC Remote Access: Allows assigned Cisco TAC engineers to collect diagnostics remotely using show commands; it does not make device changes and helps reduce back-and-forth communication with TAC

Note: Accelerated Support Access settings are available on Cisco IQ SaaS and apply to registered Cisco IQ Link on-premises instances. These settings are configured per the Cisco IQ Link instance under the Administration section.

To enable or disable remote access:

  1. Choose Home > System Settings > Data Connectors.

  2. Navigate to the relevant Cisco IQ Link instance.

    Accelerated Support Access Option
    Accelerated Support Access
    Option
  3. Click More Options > Accelerated Support Access. The Accelerated Support Access page displays.

    Accelerated Support Access
    Accelerated Support Access
  4. Use the Enable/Disable toggle to turn Rapid Resolution via Cisco IQ Link or TAC Remote Access on or off. Changes take effect immediately for the selected Cisco IQ Link instance.

Service Contracts

Linking contracts unites data from contracts associated with different team members and incorporates devices not connected to your inventory via telemetry, centralizing support coverage visibility and preventing renewal surprises. Linking contracts requires the contract number used to open support cases.

Note: You can only add and view contracts for which your Cisco ID is explicitly entitled to. Access to these contracts is determined by your organization’s profile and your association with specific service agreements.

Note: For contract number support, contact your Partner or Cisco sales representative.

Key benefits of Service Contracts include:

  • Creation of a centralized view of your organization’s support coverage

  • Customizable dashboards that allow you to stay ahead of your renewals months in advance

  • Expansion of inventory visibility to include assets not connected to telemetry or part of air-gapped environments

Adding an Initial Contract

To add a contract from the Service Contracts page:

  1. Click Add contract. The Add Contract page displays.

Note: Additional contracts can be added after an initial contract is added to the account.

  1. Enter the Contract number.

  2. Click Add contract. The contract is added to the account.

Note: After a Service Contract is added, contract-based additions to your Inventory are typically reflected within one (1) hour. Extremely large submissions (for example, contracts with several tens of thousands devices) may take marginally longer.

You can view service contract details by navigating to the Assets module under System Settings > Assets > Service Contracts. For more information about Service Contract details, see Service Contracts.

Adding Additional Contracts

After an initial contract is added, you can add additional contracts:

  1. Click Add contract. The Add Contract page displays contracts available to add to the account.

    Adding Additional Contracts
    Adding Additional Contracts
  2. Check the check box(es) of the contract(s) to add to the account.

  3. Click Save. The additional contracts are added to the account.

Note: After a Service Contract is added, contract-based additions to your Inventory are typically reflected within one (1) hour. Extremely large submissions (for example, contracts with several tens of thousands devices) may take marginally longer.

Removing Service Contracts

To remove a service contract:

Remove Service Contract
Remove Service Contract
  1. Choose the More Options icon > Remove.

    Remove Service Contract Confirmation
    Remove Service Contract
    Confirmation
  2. Click Remove to confirm.

File Upload

Assets can be added to Cisco IQ by uploading a CSV file, providing a path to inventory visibility for hardware that is not connected through a cloud controller or on-premises collector. The CSV must include each asset’s serial number; software version, hostname, and location are optional. Uploaded assets are validated against Cisco’s records and display in Assets > Inventory under a Customer Upload data source.

Prerequisites and Limitations

Before uploading your inventory file, review the following requirements and limitations:

  • Initial Contract: An initial contract must be added to your Cisco IQ system settings before uploading an inventory file. See Adding an Initial Contract for more information.

  • Serial Number: Your inventory file must include a Serial Number column. The serial number is the primary field Cisco IQ uses to process your upload. You may include additional columns from the upload template (for example, Hostname, IP Address, or Site Location); these columns are accepted but not currently used.

  • Supported Products: Only assets for Cisco IQ-supported products are accepted. Serial numbers for unsupported products are rejected. For a current list of supported products and equipment types, see the Cisco IQ Supported Product List.

  • Account Ownership Validation: Each serial number is validated against your organization’s Cisco account scope. Serial numbers that cannot be verified as belonging to your organization are rejected and do not display in your upload results.

  • Upload Behavior: Each inventory file upload replaces your previous upload entirely. Cisco IQ does not currently merge or append new records to an existing upload.

Uploading Files

To upload a file:

  1. Navigate to System Settings > File Upload. The File Upload page displays.

  2. Click Upload File. The Upload File window opens.

    Upload File
    Upload File
  3. Click Download template. A template downloads.

    Serial Numbers
    Serial Numbers
  4. Open the template file and edit the serial_number column.

Note: The hostname, software_version, and location columns are optional.

  1. Save the file.

  2. Navigate back to Cisco IQ. Select or drag-and-drop the file to the Upload field.

  3. Click Upload to confirm.

Package Catalog

The Package Catalog provides a centralized location to browse and download software packages, modules, rules, entitlements, and system components and are intended for Cisco IQ On-Premises deployments.

Package Catalog
Package Catalog

To access the Package Catalog, navigate to Home > System Settings > Package Catalog. The Package Catalog page displays. On this page, available software instances display as availability cards. Each availability card displays a software instance’s name, description, publisher, and version.

Viewing Details for Software Instances

To view release notes for a software instance, click Details. A window opens with the instance’s most recent release notes. To view previous release notes, choose a release version from the drop-down list.

Cisco IQ Link securely collects and transmits asset telemetry from your on-premises network to Cisco IQ, enabling AI-powered predictive insights.

To download Cisco IQ Link:

  1. From the Cisco IQ Link availability card, choose Download options > Installation packages. The Cisco IQ Link Installation Package window opens.

  2. Select one of the following Hypervisor options from the drop-down list:

    • ESXi: for VMware ESXi

    • Hyper-V: for Microsoft Hyper-V

    • KVM: for Linux Kernel-based Virtual Machine (KVM)

  3. Select a Version from the drop-down list.

  4. Click Download to save the file locally.

Note: Installation files are large (10-25 GB); ensure you have sufficient disk space before downloading.

  1. Deploy the file on your data center. See the Cisco IQ Link Getting Started Guide for more information.

Installing Cisco IQ Virtual Appliance

Cisco IQ Virtual Appliance is an on-premises component of Cisco IQ designed to offer complete application lifecycle management in an air-gapped environment while keeping data fully confidential.

To download Cisco IQ Virtual Appliance:

  1. From the Cisco IQ Virtual Appliance card, choose Download options > Installation packages. The Cisco IQ Virtual Appliance Installation Package window opens.

  2. Select one of the following Hypervisor options from the drop-down list:

    • ESXi: for VMware ESXi

    • Hyper-V: for Microsoft Hyper-V

    • KVM: for Linux KVM

  3. Select a Current version from the drop-down list.

  4. Select a Target version from the drop-down list.

  5. Click Download to save the file locally.

Note: Installation files are large (10-25 GB); ensure you have sufficient disk space before downloading.

  1. Deploy the file on your data center. See the Cisco IQ Virtual Appliance Getting Started Guide for more information.

To upgrade Cisco IQ Link:

  1. From the Cisco IQ Link availability card, choose Download options > Upgrade packages. The Cisco IQ Link Upgrade Package window opens.

  2. Choose the Current version from the drop-down list.

  3. Choose the desired Target version from the drop-down list.

  4. Click Download to save the file locally.

Note: Installation files are large (10-25 GB); ensure you have sufficient disk space before downloading.

  1. Deploy the file on your data center. See the Cisco IQ Link Getting Started Guide for more information.

Downloading Modules

A module is a standalone software package providing core functionality within the Virtual Appliance. It is an independent service with its own lifecycle, allowing for installation, maintenance, and resizing. The Resource consumption, including CPU, GPU, and RAM is dynamically assigned based on the deployment size (Small, Medium, or Large) selected during the initial installation.

Note: The Assets module is installed by default. It is recommended to upgrade the Assets module to the latest version.

To download a module:

  1. Navigate to System Settings > Package Catalog.

    Insights Panel
    Insights Panel
  2. From the desired module card, click Download options > Installation packages. The Download window opens.

  3. Choose a System Version from the drop-down list.

  4. Click Download to save the file locally.

Note: Installation files are large (10-25 GB); ensure you have sufficient disk space before downloading.

See the Cisco IQ Virtual Appliance Operations Guide for more information.

Downloading Rules

A rule is a specialized component or “add-on” that extends or modifies the functionality of an existing application. Rules are not designed to run as standalone programs but they are “plugged into” an application to provide specific rules, logic, or features. Rules are tied to specific modules. When a rule is installed, it is linked to the module it supports. Rules allow the system to be updated or customized without requiring a full upgrade of the core application. If a new set of rules or features is needed, you can simply add a new rule to the existing module.

To download a rule:

  1. Navigate to System Settings > Package Catalog.

  2. From the desired rule card, click Download.

  3. Choose a Target app version from the drop-down list.

  4. Click Download to save the file locally.

Note: Installation files are large (10-25 GB); ensure you have sufficient disk space before downloading.

See the Cisco IQ Virtual Appliance Operations Guide for more information.

Downloading Entitlements

An Entitlement provides validation of your organization’s right to use specific software features, applications, or services.

To download an entitlement:

  1. Navigate to System Settings > Package Catalog.

  2. From the entitlement card, click Create record. The Create entitlement bundle window opens.

    Create Entitlement Bundle
    Create Entitlement Bundle
  3. Enter a Password. Refer to the password creation rules that display on screen.

  4. Enter the same password again in Confirm Password.

  5. Choose the preferred Asset scope radio button.

Note: If you chose Selected assets radio button, click the check boxes of all applicable assets.

  1. Click Create record. Wait for the record to generate.

Note: The record creation process requires this page to remain open. Navigating to another screen will interrupt the process and the record will need to be regenerated.

  1. Click Download record to save the file locally.

Note: Installation files are large (10-25 GB); ensure you have sufficient disk space before downloading.

See the Cisco IQ Virtual Appliance Operations Guide for more information.

Common Module Features

Analyzing Data

The Insights panel delivers AI-driven analysis of the data on that page, providing actionable insights to improve the security and health of your network environment.

Note: The Insights feature is only available on select pages.

Insights Panel
Insights Panel

The following options are available inside the Insights panel:

  • Click the Expand icon to expand the panel and display additional insights

  • Click the Thumbs Up or Thumbs Down icon to provide feedback on the AI-generated information

  • Click Full Analysis to display additional information, deeper analysis, and visualizations like graphs, dashboards, and charts

Full Analysis
Full Analysis

The following options are available within a full analysis:

  • Click Download PDF to save an offline copy of the analysis, for your records or for collaboration

Exporting Information

The export feature allows you to export custom views for Assets and Security information in .xls or .csv format.

Note: The export feature is only available for select pages.

To export information from a page:

  1. Navigate to the page.

    Exporting Inventory in the Assets Module
    Exporting Inventory in the Assets
    Module
  2. Click Export. The Export Options display.

    Export Options
    Export Options
  3. Select a File type.

  4. Check the check box(es) in the desired column(s).

  5. Click Export. The file downloads to the browser’s local download folder.

Table Settings

You can configure table settings to create custom and refined views for different module features.

Table Settings
Table Settings

To change the columns that display on selected pages, click the Table Settings icon. The Table settings display.

Table Setting Options
Table Setting Options

Changing Table View

To change the table view:

  1. Select one of the following Table Density options:

    • Condensed: Minimizes visual elements and spacing to display more information

    • Compact: Reduces whitespace and tightens spacing between UI elements

    • Comfy: Utilizes more whitespace and larger spacing between elements

    • Spacious: Emphasizes abundant whitespace and larger UI elements

  2. Click Apply.

Adding and Removing Columns

To add or remove columns:

  1. Select or clear the Column Settings check box(es).

  2. Click Apply.

Note: The Name column cannot be removed from the table view.

Changing Column Order

To change the column order:

  1. Drag-and-drop the column name to arrange the items in the desired order.

  2. Click Apply.

Customizing Dashboards

The Custom Dashboard feature enables you to personalize standard dashboards through a range of intuitive customization options:

  • Rearrange dashboard widgets or panels using the drag-and-drop functionality

  • Remove any components that are not relevant to your workflow

  • Your personalized dashboard layout is securely stored to your user profile and automatically applied across all sessions and devices

  • Restore the original dashboard layout with a simple reset option

To customize a dashboard:

  1. Navigate to the dashboard.

    Customize
    Customize
  2. Click Customize.

    Edit Dashboard
    Edit Dashboard
  3. Change the dashboard as desired:

    • Rearrange: Drag-and-drop the widgets into the desired layout

    • Remove: Click the Delete icon to remove a widget

    • Reset: Click Reset to default to reset the dashboard to its original layout

  4. Click Save. A Dashboard Saved message displays.

  5. Your dashboard layout is automatically applied across all sessions and devices.

Customizing Filters

You can save custom filter configurations for any dashboard view, enabling you to easily return to your preferred settings as needed. All filter preferences are securely stored on a per-user, per-account basis, ensuring a personalized and consistent experience each time you access Cisco IQ.

Creating a Filter

To create a custom filter:

  1. Navigate to the dashboard.

  2. Click Filters.

    Filters
    Filters
  3. Choose the desired filters from the drop-down lists.

  4. Click Save Filter. The Name saved Filter window opens.

    Filter Name
    Filter Name
  5. Enter a Filter name.

  6. Click Save Filter to confirm.

Editing a Filter Name

To edit a custom filter:

  1. Click Filters.

    Manage Saved Filters
    Manage Saved Filters
  2. Click the Manage saved filters icon.

  3. Navigate to the filter.

    Edit Filter
    Edit Filter
  4. Click the Edit icon. The Name saved Filter window opens.

  5. Edit the filter name.

  6. Click Save Filter to confirm.

Deleting a Filter

To delete a custom filter:

  1. Click Filters.

  2. Click the Manage saved filters icon.

  3. Navigate to the filter.

  4. Click the Delete icon. The Delete saved filter window opens.

    Delete Saved Filter Confirmation
    Delete Saved Filter
    Confirmation
  5. Click Yes, delete to confirm.

Changing Language Options

Cisco IQ supports English, Japanese, Korean, Mandarin, and Spanish across all modules and the AI Assistant. Cisco IQ detects your language preference and displays the UI in that language, defaulting to English when the language is not yet supported.

Note: For some AI Assistant use cases, non-Latin and non-English responses may not yet be fully supported and responses may return in English.

To manually change your language:

  1. Click the User Profile icon.

    Language
    Language
  2. From the Language section, choose an option from the drop-down list.

Reporting an Issue

You can report an issue for Cisco IQ. For more detailed information about Support module capabilities, see Support Module.

Note: Only use Report an Issue for Cisco IQ issues; you must open a support case with TAC for device issues.

To create a case:

  1. Click the Help icon > Report an Issue. The Report an Issue window opens.

    Report an Issue
    Report an Issue
  2. Provide the required details.

  3. Click Submit.

Assets Module

The Assets module delivers comprehensive visibility and management capabilities and serves as the foundation of Cisco IQ, providing a centralized listing of all devices within an organization. By collecting information from multiple sources, it acts as a single source of truth for device inventory. Maintaining a complete and accurate asset list is essential, as other modules within Cisco IQ — such as the Assessments module — rely on this data to assess the health and security of your devices.

Home Menu
Home Menu

Core Concepts

The Assets Module is built on the following core concepts:

  • Asset: Any physical hardware device that is inventoried and managed as part of Cisco’s service delivery with detailed tracking of its identity, function, service coverage, and lifecycle

  • Contract-Sourced Assets: Assets ingested into inventory directly from linked Service Contract data, rather than through telemetry. Cisco IQ ingests the following equipment types from contract data: Chassis, Modules, Power Supplies, and Fans. These assets are visible in the Inventory even if no telemetry connection is present

  • Last Date of Support (LDOS): End-of-life and end-of-support milestone tracking for Cisco products

  • Service Coverage: Active support contracts, warranties, and entitlement levels associated with a specific piece of hardware or software

  • Asset Tag: A user-defined label assigned to an asset for organization, filtering, and operational workflows

  • Device Signal: Refers to when Cisco last observed a device (by its serial number) based on device telemetry, support cases, and service coverage updates; Asset telemetry data is ingested and enriched through a multi-layer data pipeline

Accessing the Assets Module

To access asset management features in Cisco IQ, choose the Home menu > Assets or navigate to the Modules section under Home > Launchpad and click Assets. The Overview page displays.

Assets Overview

The Overview page displays a dashboard that enables you to quickly evaluate the health and status of devices.

Assets Overview
Assets Overview

The dashboard displays the following information:

  • Total Assets: The total number of assets within the Cisco IQ account

  • Covered Assets: The total number and percentage of assets covered by service contracts

  • Uncovered Assets: The total number and percentage of assets not covered by service contracts

  • Assets Covered by Service Contracts: A breakdown of the number of assets — hardware or software — that service contracts cover, categorized by entitlement level

  • Last Date of Support Snapshot: A breakdown of the number of assets past LDOS or reaching LDOS

  • Key Asset Metrics: Additional key metrics such as telemetry status, critical security advisories, and LDOS information

    • Assets with Telemetry Enabled: Total number and percentage of assets with telemetry enabled

    • Assets without Telemetry Enabled: Total number and percentage of assets without telemetry enabled

    • Assets with Critical or High Security Advisories: The percentage of total assets with telemetry enabled and have critical or high security advisories

    • Assets by Criticality: A breakdown of the priority assigned to a device relative to other devices in the network

  • Asset Breakdown: A detailed display of asset information, such as product families, install-at locations, software versions, and asset roles

Filtering Views for Assets

You can filter the dashboard view by choosing a filter from the drop-down lists or clicking Filters and choosing an option from the list of available filters.

Note: Some filters may be hidden depending on screen zoom settings.
Different filters are available depending on your roles and permissions.

Viewing Details for Assets

When clicking View Details, the page redirects to the Inventory page. See Inventory for more information.

Asset Criticality Insights

Cisco IQ includes Asset Criticality Insights, a new capability in the Assets module that predicts the functional role and business importance of network devices. By analyzing device configurations and enabled features, Asset Criticality Insights helps you identify which assets have the greatest impact on your network — so you can prioritize them for security remediation, software upgrades, EOL planning, and coverage decisions.

Note: Asset Criticality Insights are available exclusively for assets with Standard or Signature levels that have active telemetry connections. Please ensure your assets meet the configuration requirements to populate these insights within the dashboard.

Asset Criticality Insights are available in the Assets app in the following areas:

  • Assets Overview: Filter and view summary breakdowns by Asset Criticality Insights attributes

  • Assets Inventory: Display, search, filter, and sort devices by Role and Importance

  • Asset Details: View Role and Importance for individual devices, with informational tooltips explaining each value

Overriding Role and Importance Classifications

Cisco IQ automatically predicts the Role and Importance of each asset based on telemetry data. Account Administrators can manually correct these classifications when the automated prediction does not accurately reflect the asset’s function or criticality in the network.

Note: Override controls are available to Account Administrators only. Role and Importance values are read-only for all other user roles.

Overriding Classifications from the Inventory Table

To override Role or Importance for one or more assets:

  1. Navigate to Assets > Inventory.

  2. Check the check box of the desired asset row. To update multiple assets simultaneously, check multiple check boxes.

    Edit Assets
    Edit Assets
  3. Click Edit assets. The Edit Selected Assets panel displays.

    Editing Selected Assets
    Editing Selected Assets
  4. In the Role or Importance fields, choose the correct value from the drop-down list.

  5. Click Update to confirm the override.

Note: To remove a previously configured override and return to the automated prediction, choose the Reset to default option from the Role or Importance drop-down lists.

Overriding Classifications from Asset Details

To override Role or Importance from the asset detail view:

  1. Navigate to Assets > Inventory and click an asset.

  2. In the Details tab, click Edit.

  3. Navigate to the Role and Importance fields.

    Role and Importance Fields in Details
    Role and Importance Fields in
    Details
  4. Choose an option from the Role and Importance drop-down lists.

  5. Click Save to confirm.

Inventory

The Inventory page provides a list of all Cisco assets within the Cisco IQ account.

Inventory
Inventory

Searching and Filtering Views for Asset Inventory

You can filter the list view by choosing a filter from the drop-down lists or clicking Filters and choosing an option from the list of available filters. You can also search for assets by entering the asset name in the Search field.

Note: Some filters may be hidden depending on screen zoom settings.
Different filters are available depending on your roles and permissions.

Inventory Analysis

The Insights panel on the Inventory page displays an AI-driven analysis that provides a summary of assets with a focus on support coverage, connectivity, and milestones. Click Full Analysis for visualizations like graphs, dashboards, and charts which provide additional insights. See Analyzing Data in Common Module Features for more details.

Exporting Inventory

Click Export to save a filtered inventory list in .xls or .csv format. See Exporting Information in Common Module Features for more details.

Viewing Asset Details

Click an asset to view asset details. An asset’s detail view displays with the following tabs:

  • Details: Displays asset details such as product, signal data, identity, location, warranty, and coverage information
Asset Details
Asset Details
  • Product Alerts: Displays related product alerts such as Security Advisories and Field Notices

  • Hardware: Provides a detailed timeline view for hardware EOL (for example, End of Sale, Last Ship, and Last Date of Support dates)

  • Software: Provides a detailed timeline view for software EOL

Asset Tags

Asset tags are custom labels you assign to inventory assets in Cisco IQ. A tag is a key:value pair — for example, Environment:Prod or Label:Campus — that you define. You can assign tags to individual assets or many assets at once, and you can filter your inventory by tag to quickly find the assets you care about.

Note: After a tag is created by an Account Administrator, you can assign a tag to an asset.

Creating and Deleting Asset Tags

See Tags in System Settings for more information about creating and deleting asset tags.

Note: Only Account Administrators can create and delete tags.

Assigning Tags

Assigning tags to selected assets in the Inventory view enables the organization and categorization of assets for enhanced filtering, reporting, and management.

To assign a tag to an asset:

  1. Navigate to Assets > Inventory.

    Tagging Assets
    Tagging Assets
  2. Select the check boxes of the desired assets.

  3. Click Manage Tags. The Manage Tags window opens.

    Assigning Tags
    Assigning Tags
  4. In the text field, input or select the tag name from the existing options and press Enter.

Note: Tags are in key:value format (for example, City:NYC).

  1. Click Apply.

Removing Asset Tags

To remove a tag from one or more assets:

  1. Navigate to Assets > Inventory.

  2. Select the check box next to one or more assets.

  3. Click Manage tags. The Manage tags window opens.

  4. Click the X on any tag to remove it from the selection.

  5. Click Apply.

Using Asset Tags as Filters

After creating a tag, you can use the tag as a filter.

To use a tag as a filter:

  1. Navigate to the Inventory page.

  2. Click Filters. The Filters window opens.

    Using Tag as Filter
    Using Tag as Filter
  3. From the Tags drop-down list, check the check boxes of the desired tags. After selecting the tag, the view on the Inventory page updates to the filtered view.

Service Contracts

The Service Contracts page streamlines support contract oversight by providing summaries and detailed contract information, supporting effective renewal planning and coverage strategies.

Service Contracts
Service Contracts

Searching and Filtering Views for Service Contracts

You can filter the list view by choosing a filter from the drop-down lists. You can also search for service contracts by entering the contract number in the Search field.

Exporting Service Contracts

Click Export to save a filtered list of contracts in .xls or .csv format. See Exporting Information in Common Module Features for more details.

Services EA Summary

The Services Enterprise Agreement (EA) Summary page provides a consolidated view of Install Base growth across your asset portfolio. Data is sourced directly from Cisco’s Install Base records, giving you and Account teams a consistent view of portfolio changes over time.

Services EA Summary
Services EA Summary

The Services EA Summary page displays the following information:

  • Assets Added: New assets added to the Install Base during the reporting period

  • Net Change: The overall change in Install Base size for the reporting period

Note: Access to the Services EA Summary page may be subject to role and permission requirements. Contact your Account Administrator if this page is not visible in your navigation.

  • Asset Growth: A summary of inventory changes over a configurable time period (for example, the number of assets added, removed, or changed in service level or location within a selected data range); to change the time period displayed, select a data range from the drop-down list

Note: Asset Growth data is sourced automatically from Cisco’s Install Base records. No additional configuration is required.

End of Life

The Hardware End of Life and Software End of Life pages provide detailed EOL information, equipping you with the support needed to proactively manage product refresh cycles and support coverage. Clicking an asset on the End of Life pages redirects you to the relevant asset on the Inventory page.

Software End of Life
Software End of Life

End of Life Analysis

The Insights panel on the End of Life page displays an AI-driven overview of assets with a defined Last Day of Support. Click Full Analysis for visualizations like graphs, dashboards, and charts which provide additional insights. See Analyzing Data in Common Module Features for more details.

Exporting End of Life

Click Export to save a filtered list of EOL assets in .xls or .csv format. See Exporting Information in Common Module Features for more details.

Assessments Module

The Assessments module provides an assessment framework that enables you to proactively investigate and mitigate risks related to security, stability, capacity, compliance, and aging, keeping networks secure, stable, and reliable.

Core Concepts

The Assessments module is built on the following core concepts:

  • Assessment: A systematic evaluation of infrastructure entities against predefined criteria to measure performance, compliance, security, or operational capability; Assessments are triggered on demand, on a schedule, or by an event

  • Assessment Execution: An instance or single run of an assessment; Each execution creates a new execution record that tracks the scope, trigger mechanism, timestamp, and resulting data produced by the evaluation

  • Finding: A validated, actionable observation identifying a gap, risk, issue, or noteworthy state. Findings represent the ground-level data during an evaluation

  • Insight: A higher-level analytical conclusion derived from patterns or trends across multiple findings. Insights interpret what findings mean in a broader business or operational context

  • Recommendation: A specific, actionable prescription linked to findings or insights; Recommendations provide clear guidance on the necessary steps to address identified issues or capitalize on opportunities

  • Report: A structured document that aggregates findings, insights, and recommendations for a target audience; Reports are the primary deliverable for communicating assessment outcomes to customers, executives, and technical teams

Accessing Assessments Module

Assessments
Assessments

To access security and assessment features in Cisco IQ, choose the Home menu > Assessments or click Assessments from the Module section of the Home page > Launchpad tab. The Assessments Overview page displays.

Assessments Overview

The Assessments Overview page displays the following dashboard:

Assessments Overview
Assessments Overview

The dashboard displays the following information:

  • Security Advisory Assessments: Displays assessments of security advisories, categorized by Critical and High severity

  • Security Hardening Assessments: Displays assets failing security hardening rules, categorized by Critical, High, Medium, Low, and Informational severity

  • Configuration Assessments: Displays assets failing configuration best practice rules, categorized by Critical, High, Medium, Low, and Informational severity

  • Quantum Safe Infrastructure: Displays Quantum Safe Migration Timeline, Quantum Safe Pillars, and Quantum Safe Readiness

  • Field Notice Assessments: Displays assessments of field notices, categorized by Critical, High, Medium, and No severity

  • Software Release Conformance Assessments: Displays assessments of software versions against organizational standards, categorized by Conformant or Non-Conformant statuses

  • Certificate Expiration Assessments: Displays assets with digital certificates nearing expiration, categorized by certificate expiry timeframe

Note: You can only view the assets that you are entitled to access.

Findings by Asset

The Findings by Asset page provides you with list of assets that have been evaluated using at least one of the following assessments: Security Advisories, Security Hardening, Configuration, Quantum Safe Infrastructure, Field Notices, Software Release Conformance, and Certificate Expiration.

Findings By Assets
Findings By Assets

Searching and Filtering Views for Findings by Asset

You can filter the list view by clicking Filters and choosing from the list of available filter options. You can also search for Findings by Asset in the Search field.

Note: Some filters may be hidden depending on screen zoom settings.
Different filters are available depending on your roles and permissions.

Exporting Findings by Asset

To export the Findings by Asset list view, click Export. See Exporting Information for more information.

Viewing Findings by Asset Details

To view Findings by Asset details, click an Asset. The following tabs display details for the selected asset:

  • Summary: Provides detailed asset information including the number of Security Advisories, Security Hardening, Configuration, Quantum Safe Infrastructure, Field Notices, Software Release Conformance, and Certificate Expiration

  • Security Advisories: Provides a list of related Security Advisory assessments

  • Security Hardening: Provides a list of assets failing Security Hardening rules

  • Configuration: Provides a list of assets failing Configuration Best Practice rules

  • Field Notices: Provides a list of related Field Notice assessments

  • Quantum: Provides the risk score and security metrics

  • Software Version: Provides details regarding the current software version

  • Priority Bugs: Provides a list of high-priority software bugs and known caveats applicable to the asset

  • Certificate Expiration: Provides a list of digital certificates associated with the asset and their upcoming expiration dates

Findings by Asset Details
Findings by Asset Details

When clicking View Details on a tile, the page redirects to the relevant page within the module.

When clicking View full asset details, the asset detail view page displays.

Security Advisories

Security Advisory assessments identify vulnerabilities and prioritize them based on their risk, severity, and criticality, thereby enhancing the organization’s risk management capabilities. Security Advisories deliver granular insights into vulnerabilities, help accelerate mitigation of critical threats, and ensure alignment with compliance and business objectives. This strengthens security posture, optimizes resource allocation, and fosters resilience against evolving threats across the enterprise. Security Advisories are automatically updated in Cisco IQ after they are released.

The Security Advisories page provides a list of all Security Advisories with vulnerabilities detected within the organization. Clicking an advisory from the Security Advisory assessments list navigates to the corresponding detail view.

Security Advisories
Security Advisories

Searching and Filtering Views for Security Advisories

You can filter the list view by clicking Filters and choosing from the list of available filter options. You can also search for Security Advisory assessments by entering the assessment name in the Search field.

Note: Some filters may be hidden depending on screen zoom settings.
Different filters are available depending on your roles and permissions.
Missing severity values display as “–” with a descriptive tooltip.

Exporting Security Advisories

To export Security Advisory assessments, click Export. See Exporting Information for more information.

Viewing Security Advisory Assessment Details

Click an Assessment to view additional details. The details page provides information such as Common Vulnerability Scoring System (CVSS) Score, Common Vulnerabilities and Exposures (CVE), Severity, and a link to the referenced Cisco Security Advisory.

You can view the following types of results in the Assessment outcome table:

  • Affected: Indicates that the asset or component has a confirmed vulnerability that can be exploited by an attacker, requiring remediation

  • Potentially Affected: Indicates that the asset or component shows signs that may lead to vulnerability, but it is not definitively confirmed; further investigation may be needed

Security Advisories Details
Security Advisories Details
Searching and Filtering Views for Asset Assessment Results

You can filter the list view by clicking Filters and choosing from the list of available filter options. You can also search for assets by entering the asset name in the Search field.

Note: Some filters may be hidden depending on screen zoom settings.
Different filters are available depending on your roles and permissions.

Viewing Asset Assessment Results

To view details of an assessment result, click an asset from the Assessment Outcome table. The asset’s Assessment Result details page displays.

Result Details
Result Details
Exporting Asset Results for Security Advisories

To export asset results, click Export. See Exporting Information for more information.

Security Hardening

Security Hardening provides automated, near real-time visibility into the security posture of your network infrastructure by continuously evaluating routers, switches, and firewalls against industry-standard benchmarks. It identifies configuration gaps and provides actionable remediation guidance, enabling administrators to effectively reduce the attack surface and maintain consistent alignment with Cisco’s rigorous security best practices. By centralizing compliance monitoring and simplifying the hardening process, the module transforms security management from a reactive task into a proactive, data-driven strategy, ensuring a resilient and secure enterprise network.

Note: Security Hardening Assessments are available exclusively for assets with Standard or Signature support tiers.

Viewing Security Hardening Assessments

The Security Hardening Assessment page displays the following information:

Security Hardening
Security Hardening
  • About the Assessment: Provides additional details by summarizing the purpose of the assessment

  • Execution Outcome: Provides a summary of asset assessment results, including the total number of Rule evaluations and Assets included

  • Rule evaluations: Provides detailed information about the rule, including Severity, Assets Evaluated, Did Not Pass, Passed, Inconclusive, Not Applicable, and Software type

    • Severity: Provides the level of importance or impact of the rule evaluation

    • Assets Evaluated: Provides the total number of assets that were assessed against the rule criteria

    • Did Not Pass: Provides the assets that failed to meet the rule criteria during the assessment

    • Passed: Provides the assets that met the rule criteria during the assessment

    • Inconclusive: Provides the assets for which the assessment could not determine failure

    • Not Applicable: Indicates the assets or scenarios where the rule does not apply or is not relevant

    • Software type: Provides the software type of assets

Searching and Filtering Views for Rules

You can filter the list view by clicking Filters and choosing from the list of available filter options. You can also search for a rule by entering the rule name in the Search field.

Note: Some filters may be hidden depending on screen zoom settings.
Different filters are available depending on your roles and permissions.

Viewing Rule Evaluation Details

To view additional details about a rule evaluation, click a rule. The rule’s evaluation details page displays with the following information:

Rule View
Rule View
  • About the Rule: Provides details about the rule such as Severity, Software type, Version, and Assets evaluated and includes descriptive labelled links to relevant source documentation

  • Results Summary: Provides a summary of asset results related to the rule such as Passed, Did not pass, Inconclusive, and Not applicable

  • Assets Results: Provides a list of assets with details such as Asset, Result, Product ID, Serial Number, IP Address, and Support Tier

Searching and Filtering Views for Asset Rules

You can filter the list view by clicking Filters and choosing from the list of available filter options. You can also search for asset assessment results by entering the asset name in the Search field.

Note: Some filters may be hidden depending on screen zoom settings.
Different filters are available depending on your roles and permissions.

Exporting Asset Results

To export assessment results for rules, click Export. See Exporting Information for more information.

Searching and Filtering Views for Asset Results

You can filter the list view by clicking Filters and choosing from the list of available filter options. You can also search for asset results by entering the asset name in the Search field.

Note: Some filters may be hidden depending on screen zoom settings.
Different filters are available depending on your roles and permissions.

Viewing Asset Results for Security Hardening

Click an asset from Asset Results to view its details. The asset’s result details page displays information according to your entitlement level or tier.

  • Standard Tier

    Security Hardening Standard Tier
    Security Hardening Standard Tier
    • Finding Details: Provides information about the configuration deviations identified during the assessment along with evidence logs

    • Recommendations: Provides guidance to address the findings and ensure configuration consistency

  • Signature Tier

    Security Hardening Signature Tier
    Security Hardening Signature
    Tier
    • Finding Details: Provides information about the configuration deviations identified during the assessment along with evidence logs

    • Recommendation: Provides device-level, actionable guidance with code snippet to ensure configuration consistency

Viewing Asset and Rule Information for Security Hardening

To view the details of an Asset and its rules, click the Asset and Rule Info tab. The Asset and Rule Info page displays.

Asset and Rule Info
Asset and Rule Info
  • About the Asset: Provides the details of the asset such as Product ID, Product type, IP address, Serial number, Software version, Location, and Support Tier

  • About the Rule: Provides rule details (including Severity and Software type) and the importance of that particular hardening check

Configuration

Configuration assessments evaluate your assets against recommended best practices based on Cisco’s proven expertise to detect configuration deviations that may affect availability, security, or performance across your infrastructure. Each best practice rule is assessed across your covered assets, and findings prioritized by severity to ensure configuration consistency, enhanced resilience, and reduced operational risk.

Note: Configuration Assessments are available exclusively for assets with Standard or Signature support tiers.

Viewing Configuration Assessments

The Configuration Assessment page displays the following information:

Configuration Assessment
Configuration Assessment
  • About the Assessment: Provides additional details by summarizing the purpose of the assessment

  • Summary: Provides a summary of configuration execution like Rules evaluated and Assets evaluated

  • Insights: Provides insights into identified configuration gaps generated through pattern analysis and a correlation of findings; they are displayed as intelligently grouped key cards to highlight the most critical areas that require attention

  • Rule Evaluations: Provides detailed information about the rule, including Severity, Assets Evaluated, Did Not Pass, Passed, Inconclusive, Not Applicable, Category, and Software type

    • Severity: Provides the level of importance or impact of the rule evaluation

    • Assets Evaluated: Provides the total number of assets that were assessed against the rule criteria

    • Did Not Pass: Provides the total number of assets that failed to meet the rule criteria during the assessment

    • Inconclusive: Provides the total number of assets for which the assessment could not run

    • Passed: Provides the count of assets that met the rule criteria during the assessment

    • Not Applicable: Indicates the count of assets where the rule does not apply or is not relevant

    • Category: Provides the domain area to which the rule belongs

    • Software Type: Indicates the type of software assets to which the rule applies

Searching and Filtering Views for Rules

Rule Evaluations
Rule Evaluations

You can filter the list view by clicking Filters and choosing from the list of available filter options. You can also search for a rule by entering the rule name in the Search field.

Note: Some filters may be hidden depending on screen zoom settings.
Different filters are available depending on your roles and permissions.

Viewing Rule Evaluation Details

To view additional details about a rule evaluation, click any rule. The rule’s evaluation details page displays with the following information:

Evaluation
Evaluation
  • About the Rule: Provides details about a rule like Severity, Category, Software type, and Assets evaluated and includes descriptive labelled links to relevant source documentation

  • Results Summary: Provides overall asset results by displaying the number of assets in Passed, Did not pass, Inconclusive, and Not applicable statuses

  • Asset Results: Provides a list of assets impacted by the selected rule with result status

Note: Cisco IQ provides clear guidance when an assessment finding is “Did Not Pass”, “Passed”, “Inconclusive”, and “Not applicable” explained in the Finding Details section.

Exporting Asset Results

To export asset results for rules, click Export. See Exporting Information for more information.

Searching and Filtering Views for Asset Results

You can filter the list view by clicking Filters and choosing from the list of available filter options. You can also search for asset results by entering the asset name in the Search field.

Note: Some filters may be hidden depending on screen zoom settings.
Different filters are available depending on your roles and permissions.

Viewing Asset Results for Configuration Assessments

To view details of asset results, click an asset from the Asset results.

The asset’s result details page displays information according to your entitlement level or tier.

Configuration Signature Tier
Configuration Signature Tier
  • Finding Details: For an asset with “did not pass” result, provides information about the configuration deviations identified during the assessment along with evidence logs

  • Recommendations: Provides guidance to address the findings and ensure configuration consistency

Viewing Asset and Rule Information for Configuration Assessments

To view asset and rule information details, click the Asset and Rule Info tab.

Asset and Rule Info
Asset and Rule Info

The Asset and Rule Info page displays with the following information:

  • About the Asset: Provides the details of an asset, such as Product ID, Product type, IP address, Serial number, Software version, Location and Support tier

  • About the Rule: Provides details of a rule such as Severity, Category, and Software type

Viewing Insights

Insights are AI-generated and serve as an intelligent dashboard that synthesizes assessment data into prioritized key cards, highlighting critical configuration disparities across multiple findings. It enables you to address the most impactful infrastructure risks efficiently by focusing on these urgent areas. It also highlights strengths by identifying areas where your infrastructure is performing well as per best practices.

Insights
Insights

To view Insights details:

  1. From the Insights panel, click View all. The Insights page displays all insights.

    Insights Page
    Insights Page
  2. Click View details or click any card. The Insights detail page displays with the following information:

    Insights Detail
    Insights Detail
    • Insight: Provides a summary that highlights recurring patterns of configuration deviations identified through comprehensive analysis across multiple findings, as well as areas of excellence in your infrastructure where configurations align with best practices

    • Recommendation: Provides actionable steps to remediate the identified configuration gaps

    • Affected Assets: Provides a list of specific devices where the configuration deviation has been identified as defined under the Insight section

  3. Click Source Findings. The Source Findings page displays the detailed individual findings that support your insights.

    Source Findings
    Source Findings

    You can filter the list view by clicking Filters and choosing from the list of available filter options. You can also search for assets by entering the asset name in the Search field.

Note: Recommendations and Affected Assets are optional depending on the output of each insight.

Quantum Safe Infrastructure Assessments

Quantum Safe Infrastructure assessments evaluate your network and data environment against emerging post-quantum cryptographic standards to detect gaps in encryption and authentication protocols, providing actionable insights to strengthen your security posture and ensure long-term data integrity.

Viewing Quantum Safe Infrastructure Assessments

The Quantum Safe Infrastructure Assessment page displays the following information:

Quantum Safe Infrastructure
Quantum Safe Infrastructure
  • About the Assessment: Provides additional details by summarizing the purpose of the assessment

  • Summary: Provides a summary of configuration execution like Rules evaluated and Assets evaluated

  • Insights: Provides insights into identified configuration gaps generated through pattern analysis and a correlation of findings; they are displayed as key cards grouped by risk level to highlight the most critical areas that require attention

  • Rule Evaluations: Provides detailed information about the rule, including Severity, Did Not Pass, Passed, Unable to Evaluate, Not Applicable, and Category

Searching and Filtering Views for Rules

Quantum Safe Rule Filtering
Quantum Safe Rule Filtering

You can filter the list view by clicking Filters and choosing from the list of available filter options. You can also search for a rule by entering the rule name in the Search field.

Note: Some filters may be hidden depending on screen zoom settings.
Different filters are available depending on your roles and permissions.

Viewing Rule Evaluation Details

To view additional details about a rule evaluation, click any rule. The rule’s evaluation details page displays with the following information:

Quantum Safe Rule Details
Quantum Safe Rule Details
  • About the Rule: Provides details about a rule like Severity and Category

  • Results Summary: Provides overall asset results by displaying the number of assets in Passed, Did not pass, Inconclusive, and Not applicable statuses

  • Asset Results: Provides a list of assets impacted by the selected rule with result status

Exporting Asset Results

To export asset results for rules, click Export. See Exporting Information for more information.

Searching and Filtering Views for Asset Results

You can filter the list view by clicking Filters and choosing from the list of available filter options. You can also search for asset results by entering the asset name in the Search field.

Note: Some filters may be hidden depending on screen zoom settings.
Different filters are available depending on your roles and permissions.

Viewing Asset Results for Quantum Safe Infrastructure

To view the details of asset results, click an asset from the Asset results.

The asset’s result details page displays information according to your entitlement level or tier.

Quantum Safe Asset Details
Quantum Safe Asset Details
  • Finding Details: Provides information about the findings identified during the assessment along with evidence logs

  • Recommendation: Provides guidance to address the findings

Viewing Asset and Rule Information for Quantum Safe Infrastructure Assessments

To view asset and rule information details, click the Asset and Rule Info tab.

Quantum Safe Asset and Rule Info
Quantum Safe Asset and Rule
Info

The Asset and Rule Info tab displays with the following information:

  • About the Asset: Provides the details of an asset, such as Product ID, Product type, IP address, Serial number, Software version, and Location

  • About the Rule: Provides details of a rule such as Severity and Category

Viewing Insights

You can view insights from Quantum Safe Infrastructure.

Insights
Insights

To view an Insights details:

  1. From the AI Insights panel, click View all. The Insights page displays all insights.

    Insights details
    Insights details
  2. Click View insight or click any card. The Insights detail page displays with the following information:

    Insights details
    Insights details
    • Insight: Provides a summary that highlights recurring patterns of Quantum Safe Infrastructure deviations identified through comprehensive analysis across multiple findings, as well as areas of excellence in your infrastructure where your Quantum Safe Infrastructure aligns with recommendations

    • Recommendations: Provides actionable steps to remediate the identified Quantum Safe Infrastructure gaps

    • Affected Assets: Provides a list of specific devices where a Quantum Safe Infrastructure deviation has been identified as defined under the Insight section

  3. Click the Source Findings tab. The Source Findings page displays the detailed individual findings that support your insights.

    Insights Source Findings
    Insights Source Findings

    You can filter the table view by choosing a filter from the Quantum Safe status, Severity, and Result drop-down lists.

Note: Recommendations and Affected Assets are optional depending on the output of each insight.

Field Notices

Field Notices identify significant non-security-related product issues and organizes them based on their impact severity and criticality, enhancing the organization’s ability to manage product risks. Field Notices deliver actionable insights into product defects, accelerate mitigation through recommended upgrades or workarounds, and ensure alignment with operational and business objectives. This strengthens product reliability, optimizes resource allocation, and fosters resilience against evolving product challenges across the enterprise.

Field Notices
Field Notices

Searching and Filtering Views for Field Notices

You can filter the list view by choosing a filter from the drop-down lists. You can also search for field notice assessments by entering the assessment name in the Search field.

Viewing Assessments for Field Notices

To view additional details about a field notice, click an Assessment. The following assessment details display:

  • About the Assessments: Provides additional details by summarizing the purpose of the assessment

  • Field Notice Assessments: Displays a list of assets impacted by the selected field notice, including assets with detected vulnerabilities

Viewing Assessments for Field Notices
Viewing Assessments for Field
Notices
Searching and Filtering Views for Asset Results for Field Notices

You can filter the list view by clicking Filters and choosing from the list of available filter options. You can also search for asset results by entering the asset name in the Search field.

Note: Some filters may be hidden depending on screen zoom settings.
Different filters are available depending on your roles and permissions.

Exporting Asset Results for Field Notices

To export assessment asset results for field notices, click Export. See Exporting Information for more information.

Viewing Asset Assessment Results for Field Notices

To view an asset’s assessment result details, click an asset from Asset Results. The asset’s result details page displays.

Field Notice Asset Results Details
Field Notice Asset Results
Details

You can view the following types of results:

  • Affected: Indicates assets that meet all the criteria automatically checked for a Field Notice and require no additional manual verification to confirm they are impacted

  • Potentially Affected: Indicates assets that meet all the automatically checked criteria for a Field Notice but require additional manual verification to confirm if they are truly impacted

Software Release Conformance

The Software Release Conformance assessment checks each device against the current Suggested Software Release(s) for a specific product. This assessment runs across all supported products and shows how much of your estate is running a suggested release, so you can find opportunities for software modernization and conformance.

Viewing Software Release Conformance Assessments

The Software Release Conformance Assessment page displays the following information:

Viewing Software Release Conformance
Viewing Software Release
Conformance
  • About the Assessment: Provides additional details by summarizing the purpose of the assessment

  • Summary: Provides a summary of configuration execution like Rules evaluated and Assets included

  • Rule Evaluations: Provides detailed information about the rule, including Software Type, Severity, Assets Evaluated, Non-Conformant, Conformant, Inconclusive, and Not Applicable statuses

Searching and Filtering Views for Rules

Software Release Conformance Rule Evaluations
Software Release Conformance Rule
Evaluations

You can filter the list view by clicking Filters and choosing from the list of available filter options. You can also search for a rule by entering the rule name in the Search field.

Note: Some filters may be hidden depending on screen zoom settings.
Different filters are available depending on your roles and permissions.

Viewing Rule Evaluation Details

To view additional details about a rule evaluation, click any rule. The rule’s evaluation details page displays with the following information:

Software Release Conformance Rule Detail
Software Release Conformance Rule
Detail
  • About the Rule: Provides details about a rule like Severity, Category, Software type, and Assets evaluated and includes links to relevant source documentation

  • Results Summary: Provides overall asset results by displaying the number of assets in Conformant, Non-conformant, Inconclusive, and Not applicable statuses

  • Asset Results: Provides a list of assets impacted by the selected rule with result status

Exporting Asset Results

To export asset results for rules, click Export. See Exporting Information for more information.

Searching and Filtering Views for Asset Results

You can filter the list view by clicking Filters and choosing from the list of available filter options. You can also search for asset results by entering the asset name in the Search field.

Note: Some filters may be hidden depending on screen zoom settings.
Different filters are available depending on your roles and permissions.

Viewing Asset Results for Software Release Conformance Assessments

To view details of asset results, click an asset from the Asset results.

The asset result’s details page displays information according to your entitlement level or tier.

Software Release Conformance Assets Results
Software Release Conformance Assets
Results
  • Finding Details: Provides information about whether the device is running a current suggested software release, and explains the result

  • Recommendations: Provides the recommended release version to upgrade to

Viewing Asset and Rule Information for Software Release Conformance Assessments

To view asset and rule information details, click the Asset and Rule Info tab.

Software Release Conformance Asset and Rule Info
Software Release Conformance Asset and
Rule Info

The Asset and Rule Info page displays with the following information:

  • About the Asset: Provides the details of an asset, such as Product ID, Product type, IP address, Serial number, Software version, and Location

  • About the Rule: Provides details of a rule such as Severity, Product Family, and Software type

Certificate Expirations

Certificate Expiration assessments evaluate digital certificates deployed across your infrastructure against recommended certificate versions. It detects certificates that have already expired, and group current certificates based on when they are due to expire. Each certificate rule is evaluated across your covered assets, with findings prioritized by severity to help you maintain certificate hygiene, prevent outages, and reduce security risk.

Viewing Certificate Expirations

The Certificate Expiration Assessments page displays the following information:

Certificate Expiration Detail
Certificate Expiration
Detail
  • About the Assessment: Provides additional details by summarizing the purpose of the assessment

  • Summary: Provides a summary of configuration execution like Rules evaluated and Assets included

  • Rule Evaluations: Provides detailed information about the rule, including the Severity, Assets Evaluated, Assets Affected, Assets Not Affected, and Certificate Expiration within Timeframe

Searching and Filtering Views for Rules

Certificate Expiration Rule
Certificate Expiration Rule

You can filter the list view by clicking Filters and choosing from the list of available filter options. You can also search for a rule by entering the rule name in the Search field.

Note: Some filters may be hidden depending on screen zoom settings.
Different filters are available depending on your roles and permissions.

Viewing Rule Evaluation Details

To view additional details about a rule evaluation, click any rule. The rule’s evaluation details page displays with the following information:

Certificate Expiration Rule Details
Certificate Expiration Rule
Details
  • About the Rule: Provides details about a rule like Severity, Category, Software type, and Assets evaluated and includes links to relevant source documentation

  • Results Summary: Provides overall asset results by displaying the number of assets in Expiration within timeframe and Unable to evaluate statuses

  • Results: Provides a list of assets impacted by the selected rule with result statuses

Exporting Asset Results

To export asset results for rules, click Export. See Exporting Information for more information.

Searching and Filtering Views for Asset Results

You can filter the list view by clicking Filters and choosing from the list of available filter options. You can also search for asset results by entering the asset name in the Search field.

Note: Some filters may be hidden depending on screen zoom settings.
Different filters are available depending on your roles and permissions.

Viewing Asset Results for Certificate Expiration

To view details of asset results, click an asset from the Asset results.

The asset’s result details page displays information according to your entitlement level or tier.

Certificate Expiration
Certificate Expiration
  • Finding Details: Provides information about certificate validity

  • Recommendation: Provides actionable guidance with code snippets to address the findings and ensure consistency

Viewing Asset and Rule Information for Certificate Expiration Assessments

To view asset and rule information details, click the Asset and Rule Info tab.

Certificate Expiration Asset and Rule info Tab
Certificate Expiration Asset and Rule
info Tab

The Asset and Rule Info page displays with the following information:

  • About the Asset: Provides the details of an asset, such as Product ID, Product type, IP address, Serial number, Software version, and Location

  • About the Rule: Provides details of a rule such as Severity and Assets Evaluated

Support Module

The Support module offers a consolidated view of customer support cases. It enables you to filter, sort, and customize the case list view, providing visibility into both open and closed cases you are entitled to access.

To access the Support module in Cisco IQ, choose Home > Support or click Support from the Modules section on the Home page > Launchpad. The Overview page displays.

Support Overview

Support Overview
Support Overview

The Overview page is an interactive dashboard of graphs and widgets with the following information:

  • Cases Pending Customer Action: All open cases in “Customer Pending” status categorized by S1/S2 and S3/S4 severity

  • RMAs Pending Returns: All RMAs in “Pending” and “Overdue” status

  • Draft RMAs: All RMAs in “Customer Pending” and “Cisco Pending” status

  • Open Cases by Severity: All open cases categorized by S1 through S4 severity

  • Open Cases by Case Status: All open cases categorized by their case status

  • Opened and Closed Cases: Case volume trends over time

Note: The Opened and Closed Cases trends are only available for Standard and Signature Tier cases.

Viewing Details for Cases

Clicking View details redirects the page to the account’s Cases page. Clicking a widget or a bar from a graph on the Overview page redirects the page to the account’s Cases page with relevant filters applied. For example, clicking the S1 severity bar from the Open Cases by Severity graph redirects to the account’s Cases page with Case State set to “Open” and Severity set to “S1”. See Cases for more information.

Cases

Account Cases

Navigate to the Cases page by clicking Cases from the left-hand panel.

Cases
Cases

The Cases page displays a consolidated list of all cases associated with the contracts in your Cisco IQ account. You can configure the columns displayed in the list by clicking the Settings icon, checking the check boxes of the desired columns, and clicking Apply. The Case Number column always displays and cannot be deselected.

Available Actions

The following actions can be performed from the Cases page:

  • Open a case: Click Open a case to cross launch SCM and create a case

  • Export Data: Click Export to download all data currently displayed in the dashboard, as a CSV file

  • View Case Details: Click a case number or a table row to open a case’s detail view (see Case Detail Views for more information)

  • Close a Case: Choose an open case’s More Options icon > Close case to open the Close case window, where you can provide a reason for the closure and close the case

  • Reopen a Case: Choose a closed case’s More Options icon > Reopen case to open the Reopen case window, where you can provide a reason for the reopening and open the case

Note: Closed cases can be reopened within 14 days of closure.

Searching and Filtering Views for Cases

You can filter the list view by clicking Filters and choosing from the list of available filter options. Filters persist across sessions and logins to personalize the dashboard. The only default filter applied is “Case State: Open”. You can also search for cases by entering a case number in the Search field.

Note: Some filters may be hidden depending on screen zoom settings.

Your Cases

Navigate to the Your Cases page by clicking Your cases from the left-hand panel.

Your Cases
Your Cases

The Your Cases page displays a consolidated list of cases you are entitled to view and manage. You can configure the columns displayed in the list by clicking the Settings icon, checking the check boxes of the desired columns, and clicking Apply. The Case Number column always displays and cannot be deselected.

Available Actions

The following actions can be performed from the Your Cases page:

  • Open a Case: Click Open a case to cross launch SCM and create a case

  • Export Data: Click Export to download all data currently displayed in the dashboard, as a CSV file

  • View Case Details: Click a case number or a table row to open a case’s detail view (see Case Detail Views for more information)

  • Close a Case: Choose an open case’s More Options icon > Close case to open the Close case window, where you can provide a reason for the closure and close the case

  • Reopen a Case: Choose a closed case’s More Options icon > Reopen case to open the Reopen case window, where you can provide a reason for the reopening and open the case

Note: Closed cases can be reopened within 14 days of closure.

Searching and Filtering Views for Your Cases

You can filter the list view by clicking Filters and choosing from the list of available filter options. Filters persist across sessions and logins to personalize the dashboard. The only default filter applied is “Case State: Open”. You can also search for cases by entering a case number in the Search field.

Note: Some filters may be hidden depending on screen zoom settings.

Case Detail Views

To view a case’s details, click a case from the list.

Case Detail View
Case Detail View

The case detail view displays and provides a centralized view of a support case, allowing you to review case information, affected asset information, track TAC progress, and access available case actions. Available actions include reopening a closed case by clicking Reopen case, closing an open case by clicking Close case, and launching the AI Assistant with the case’s context by clicking Ask AI. The available tabs are described in the sections below.

Note: Fields that are AI-generated are labeled with a Star icon where applicable.

Star Icon
Star Icon
Summary

The Summary tab displays key case information, enabling you to quickly understand the current state, context, and progress of an individual support case. You can review case details and affected assets, monitor the lifecycle of your case through TAC progress details, modify contact information, and specify email addresses to receive case update notifications. Only select fields are editable.

Notes
Notes
Notes

Clicking the Notes tab opens the Notes page. You can view all notes associated with a case whether they were submitted by the customer or a Cisco Engineer.

To add a new note:

Warning: Notes cannot be deleted.

  1. Click Add note. The Add note window opens.

  2. Enter a Title.

  3. Enter the Details.

  4. Click Add.

Files
Files
Files

Clicking the Files tab opens the Files page. You can view the name, size, and date of a case’s files as well as add or delete them. Filter files by clicking Filters and choosing from the available filter options. You can also configure the columns displayed in the list by clicking the Settings icon, checking the check boxes of the desired columns, and clicking Apply.

To add a file, click Attach file. You are redirected to SCM where you can upload a file for the case.

To delete a file, check the check box(es) of the desired file(s) and click Delete. The Delete file(s) window opens. Click Delete file(s).

Note: File downloads are not supported.

Associated Bugs
Associated Bugs
Associated Bugs

Clicking the Associated bugs tab opens the Associated bugs page. You can click a bug’s ID to cross launch detailed bug information in Cisco.com’s Bug Search Tool.

Associated RMAs
Associated RMAs
Associated RMAs

Clicking the Associated RMAs tab opens the Associated RMAs page. You can configure the columns displayed in the list by clicking the Settings icon, checking the check boxes of the desired columns, and clicking Apply. The following actions can be performed from the Associated RMAs page:

  • Close a Case: Click Close case to open the Close case window, where you can provide a reason for the closure and close the case

  • View RMA Details: Click an RMA number or table row to open an RMA’s detail view (see RMA Details Views for more information)

  • Contact Cisco Logistics: Choose a row’s More Options icon > Contact Cisco logistics to contact the Cisco Logistics Team

RMAs

Account RMAs

RMAs List
RMAs List

Navigate to the RMAs page by clicking RMAs from the left-hand panel. The RMAs page displays a consolidated list of all RMAs associated with the cases in your Cisco IQ account. You can configure the columns displayed in the list by clicking the Settings icon, checking the check boxes of the desired columns, and clicking Apply.

Available Actions

The following actions can be performed from the RMAs page:

  • Export Data: Click Export to download all data currently displayed, as a CSV file

  • View RMA Details: Click an RMA number or table row to open a RMA’s detail view (see RMA Details Views for more information)

  • Contact Cisco Logistics: Choose a row’s More Options icon > Contact Cisco logistics to contact the Cisco Logistics Team

Searching and Filtering Views for Account RMAs

You can filter the list view by clicking Filters and choosing from the list of available filter options. You can also search for an RMA by entering an RMA number in the Search field.

Note: Some filters may be hidden depending on screen zoom settings.

Your RMAs

Navigate to the Your RMAs page by clicking Your RMAs from the left-hand panel.

Your RMAs
Your RMAs

The Your RMAs page displays a consolidated list of RMAs you have the necessary entitlements to view and manage. You can configure the columns displayed in the list by clicking the Settings icon, checking the check boxes of the desired columns, and clicking Apply.

Available Actions

The following actions can be performed from the Your RMAs page:

  • Export Data: Click Export to download all data currently displayed, as a CSV file

  • View RMA Details: Click an RMA number or table row to open a RMA’s detail view (see RMA Details Views for more information)

  • Contact Cisco Logistics: Choose a row’s More Options icon > Contact Cisco logistics to contact the Cisco Logistics Team

Searching and Filtering Views for Your RMAs

You can filter the list view by clicking Filters and choosing from the list of available filter options. You can also search for an RMA by entering an RMA number in the Search field.

Note: Some filters may be hidden depending on screen zoom settings.

RMA Details Views

RMA Detail View
RMA Detail View

The RMA details view provides a centralized view of an RMA, allowing you to review RMA information, track progress, and access available RMA actions. Available actions include contacting the Cisco Logistics Team, accessing tracking numbers, and scheduling asset pickups.

AI Assistant

Overview

The AI Assistant is designed to improve the understanding and usage of Cisco IQ by transforming raw data into actionable insights, recommendations, and guided actions. It integrates into existing tools where it leverages individual data sources and synthesizes intelligence across multiple data streams to deliver real-time suggestions. By providing contextual understanding that empowers you to make proactive, informed decisions and streamlining processes for customer engagement and success, the AI Assistant optimizes operational outcomes and enhances the Cisco IQ user experience.

AI Assistant capabilities include:

  • Streaming Capability: View responses as they are generated

  • Enhanced Contextual Data: Dynamic context enables seamless interactions across modules, pages, and sessions

  • Case Management Support: Create, view, and manage cases displayed in the Cases list view

  • Asset Inventory Management: Track, manage, and generate reports for an organization’s assets or resources

  • Asset Criticality: Prioritize assets for risk mitigation activities based on their role and importance within the network

  • Risk Assessment and Management: Assess and manage potential risks associated with an organization’s assets

  • Security Hardening: Compare customer device-running configurations for supported devices to related Cisco and Cybersecurity and Infrastructure Security Agency (CISA) hardening guidelines

  • Configuration: Evaluate customer device-running configurations against recommended best practices, identify configuration deviations and provide actionable recommendations

  • File Upload for Troubleshooting: Upload supported file formats and logs directly into the AI Assistant for troubleshooting

Note: File Upload for Troubleshooting supports .txt, .xls, .csv, .jpg, .pdf, .zip, .rar, .7z, .gz, .tar files up to 100 MB per file. Up to 500 MB total file upload allowed per thread.

  • Cisco IQ Questions: Answer general questions about Cisco IQ’s available and newly launched features, modules, use cases, documentation references, as well as support tiers and contacts

Note: The AI Assistant can be launched from anywhere within Cisco IQ. It is available to all users, but the capabilities offered differ based on the support tier level (Basic, Standard, or Signature).

Accessing the AI Assistant

To use the AI Assistant:

AI Assistant Icon
AI Assistant Icon
Ask AI
Ask AI
Embedded AI Assistant
Embedded AI Assistant
  1. Interact directly with the AI Assistant embedded on the Home page > Launchpad, or launch the AI Assistant from anywhere in Cisco IQ by clicking the AI Assistant icon or clicking Ask AI.

Note: When the AI Assistant is accessed by clicking the AI Assistant icon or Ask AI, data and context from the specific page where you launch it is utilized, enabling the AI Assistant to provide highly relevant insights and recommendations. By understanding your current task, it delivers personalized guidance, troubleshooting steps, and increased efficiency.

Landing Page
Landing Page

Note: You can enter a new prompt or browse the library of pre-made prompts.

LDOS Report
LDOS Report

Note: By default, the AI Assistant’s view is set to full screen. When you select a new view, the AI Assistant retains the view you previously selected.

The AI Assistant displays the following available options:

  • Previous threads: Provides the past 30 days of prompt history

  • Browse Prompts: Opens the prompt library; see Appendix A: AI Assistant Prompts for a list of all questions available in the prompt library

  • Ask the AI Assistant a question field: Text field to ask the AI Assistant a question; use full, descriptive sentences to receive better responses

  1. (Optional) For troubleshooting, click the Upload icon to upload a file or log.

  2. Choose a prompt using one of the following methods:

    • Search for prompts by entering one (1) or more key words into the Ask the AI Assistant a question field and click an available prompt

    • Enter a free-form question using descriptive, full sentences into the Ask the AI Assistant a question field and press Enter

    Prompt Library
    Prompt Library
    • Click Browse Prompts to open the prompt library, choose any of the following prompt category tabs, and click an available prompt:

      • Cases: Prompts to support case management actions such as viewing, updating, escalating, and closing cases, enabling efficient tracking and connecting with a Cisco support engineer

      • Troubleshooting: Prompts to assist with error syslog messages or configuration questions

      • Assessments – Security Advisories: Prompts related to evaluating overall network security posture, identifying critical vulnerabilities, and listing specific assets affected by high-severity security threats or configuration weaknesses

      • Assets: Prompts related to proactively managing network lifecycles by identifying assets at risk due to end-of-life status, software currency or non-conformance, security vulnerabilities, and contract coverage gaps

      • Assessments – Configuration: Prompts related to summarizing configuration assessment results, identifying configuration deviations against recommended best practices, and generating actionable recommendations

      • Assessments – Security Hardening: Prompts related to identifying recommended security baseline configurations, best practices for device hardening, and step-by-step procedures for securing Cisco network infrastructure

      • Cisco IQ: Prompts related to foundational knowledge about Cisco IQ’s available and newly launched features, modules, use cases, documentation references, as well as support tiers and contacts

      • Assessments – Quantum: Prompts related to summarizing and prioritizing network quantum readiness posture by surfacing vulnerabilities, compliance gaps, and actionable focus areas

  3. Wait for a response to generate.

Enhanced Contextual Data for the AI Assistant

The AI Assistant ensures that context is dynamic, enabling seamless interactions across modules, pages, and sessions. This ensures that every response leverages contextual data to provide highly relevant responses tailored to your question.

LDOS Summarization and Prioritization

LDOS Report
LDOS Report

The LDOS Summarization and Prioritization feature enables you to quickly identify, and address risks associated with network assets. This feature classifies assets by their expected network roles and security vulnerability status, enabling vulnerability remediation and enhancing overall service quality.

Key Benefits

Key benefits of the LDOS Summarization and Prioritization feature include:

  • Prioritized Risk View

  • Operational Impact Analysis

  • Actionable Insights

As a part of this feature, you can view a limited set of pre-seeded questions (marked by “*“) in the user interface or when viewing LDOS insights.

AI Assistant Reports

AI Assistant Report Generation

See Generating Reports from the AI Assistant for more information.

LDOS Report Generation

AI-generated, curated LDOS reports provide summaries of assets approaching or past their LDOS. The reports also highlight refresh options as well as identify security advisories and vulnerabilities to help you quickly understand your network’s risk landscape.

Analyze Response

Analyze Response
Analyze Response

When clicking Analyze Response, you receive an AI-driven summary that summarizes data and generates various visualizations like graphs, dashboards, and charts, providing insightful information.

AI Summary
AI Summary

The AI-driven summary has the following three options for managing and refining the reports:

  • Download PDF: Click Download PDF to download the report as PDF

  • Customize: Click Customize to customize prompts

  • Save: Click Save to save the report to Your Reports

Data Sources for LDOS Summarization and Report Generation

The following key data sources are leveraged by the LDOS Summarization and Prioritization feature:

  • Install Base Assets and Contracts

  • Telemetry Assets and Contracts

  • CX Signal Data

  • EOL Milestones for Hardware and Software Assets

Troubleshooting with the AI Assistant

Cisco IQ empowers you to resolve device issues independently with the AI Assistant. Built on Cisco’s certified troubleshooting tools and a proven knowledge base, this intuitive, interactive assistant provides real-time, contextual recommendations.

It is designed for day-to-day troubleshooting scenarios and helps network engineers to investigate Cisco product issues, review symptoms, and identify actionable next steps. It interprets technical details such as error messages, syslogs, software defects, release guidance, and configuration-related questions. By addressing challenges instantly, you can maintain optimal performance and save time by resolving issues without the need to open a support case.

Best Practices

When using the AI Assistant for troubleshooting, use the following best practices:

  • Be as specific as possible; include the platform, product family, and software version in your first message

Note: When launching the AI Assistant from an asset view, it already has this information.

  • Paste the exact error, alarm, or syslog text or upload a supported file format containing the errors or logs instead of paraphrasing

  • Describe what changed before the issue started, such as an upgrade, configuration update, or topology change

  • Share the impact clearly, such as whether the issue affects one device, one site, or multiple users

Cases

The Cases Management feature enables you to manage your support cases through self-service, ensuring that business applications and services are restored promptly. This feature helps you efficiently manage cases and streamline the support experience. See Support Module for more information about Case Management.

With Cases Management, you can quickly view and track your support cases in one place. It helps you check case status, review updates, follow progress, and stay informed on the next steps, making it easier to manage issues and get support faster.

Appendix A: AI Assistant Prompts

This appendix provides a detailed overview of the prompts available in the AI Assistant, organized into bullet lists by question themes.

Note: You can browse available prompts by selecting relevant suggestions as the prompt library narrows options based on your input, or you can submit your own custom prompt. AI Assistant relies on natural language input and does not include input forms such as drop-down menus, ensuring a seamless user experience.

The following prompts are available under the Cases tab:

  • Show me my open cases
  • Summarize a case
  • Show me the summary of a RMA
  • Show me the summary of a bug
  • Give me an update on a case
  • Give the most recent update and any pending action items for a case
  • Close an open case
  • Add a participant to a case and contact list
  • Create a Webex space communication about a case
  • Connect me with the engineer handling the case
  • Raise the severity level of an open case
  • Escalate an open case
  • Request a new engineer for a case
  • Re-queue an open case
  • Add note to a case

The following prompts are available under the Troubleshooting tab:

  • Why did the web GUI on my Cisco Catalyst 9800-40 controller running IOS XE 16.12.07 stop working after a software upgrade even though there were no APs connected?
  • On a Cisco Nexus N9K-C92348GC-X, an image upgrade failed with error code 0x404F0003 when upgrading directly from NX-OS 9.3(2) to 10.3(7)M. What caused the failure and what intermediate upgrade path should I follow?
  • What does the syslog message %ROUTING-BGP-5-ADJCHANGE mean on an ASR9K running IOS-XR, and what are the common causes and troubleshooting steps?
  • How do I replace SNMPv2 with SNMPv3 authPriv on a Cisco NCS5500 running IOS-XR as part of Cisco’s Resilient Infrastructure hardening recommendations?
  • How do I push the SDN certificate and telemetry configuration from Catalyst Center 2.3.7.7 to a Cisco Catalyst 9800-40 WLC running IOS XE 17.12.5 to restore health/telemetry data, and which ports must be reachable?

The following prompts are available under the Assessments – Security Advisories tab:

  • Are there any advisories related to DHCP?
  • Is there a security advisory to check for webUI privilege escalation vulnerabilities related to salt typhoon?
  • Before I enable HTTP, can you check for known security advisories or vulnerabilities related to enabling HTTP?
  • How many security advisories are vulnerable in my network?
  • How many devices are vulnerable to security advisories?

The following prompts are available under the Assets tab:

  • Summarize assets past Last Date of Support (LDOS).
  • Summarize assets reaching Last Date of Support (LDOS) in the next 12 months.
  • Generate a PPT summary report for all Last Date of Support (LDOS) assets.
  • How many sub-components will reach LDOS in the next 12 months?
  • How many different software versions are present in my top 5 software types?
  • How many assets are both covered and past their Last Date of Support (LDOS)?
  • Summarize the top 5 product families with the most devices past LDOS and affected by security advisories.
  • Summarize cards and modules past LDOS and affected by security advisories.
  • How many sub-components are hitting end of life milestones earlier than their parent chassis?
  • How many of my devices have field notices?
  • How many of my devices need a software update?
  • What is the recommended software version for Catalyst 9300 devices?
  • What are my most critical assets by role and importance?
  • How many core devices are affected by security advisories?
  • Summarize critical and high importance devices with coverage expiring in the next 12 months
  • Prioritize LDOS assets for refresh based on role and importance.
  • Prioritize uncovered or soon-to-be uncovered assets for renewal based on role and importance.
  • Prioritize expiring contracts for renewal based on role and importance of those covered assets.
  • Prioritize PSIRT vulnerabilities based on severity and role and importance of affected assets.

The following prompts are available under the Assessments – Configuration tab:

  • Can you provide a summary of my recent Configuration Assessment?
  • How many configuration best practice rules were evaluated, and how many resulted in at least one asset that did not pass?
  • What are the most common configuration deviations across my network?
  • How many assets were evaluated, and what percentage did not pass?
  • Which categories have the most deviations from configuration best practices?
  • Show breakdown of configuration best practice rules deviations by severity, category, and software type
  • Which Cisco product families have the most deviations from configuration best practices?
  • Which configuration deviations pose the highest risk to my network, and what corrective actions are recommended?
  • Which assets have the maximum of critical and high severity configuration deviations? What corrective actions are recommended?
  • Show breakdown of critical and high severity configuration deviations by asset criticality
  • Which configuration deviations pose the highest risk to my network, and what corrective actions are recommended?

The following prompts are available under the Assessments – Security Hardening tab:

  • What are Cisco security hardening best practices for network devices?
  • How do I harden my Cisco IOS XE devices?
  • List key security hardening steps for routers and switches.
  • What are recommended baseline hardening settings for Cisco devices?
  • How many assets are in violation of security hardening best practices?

The following prompts are available under the Assessments – Quantum tab:

  • Which quantum readiness rules have the highest failure counts across my network?
  • For my Signature-tier assets, how many are quantum-ready across the three security pillars (Quantum Safe Products, Quantum Safe Communication, Crypto Agility) when grouped by product family?
  • Why are devices failing quantum readiness rules, and which products contribute most to these failures?
  • What are the top 3 AI-prioritized quantum security focus areas for my Signature-tier assets?
  • What cryptographic usages are present across my device’s management, control, and data planes?

The following prompts are available under the Cisco IQ tab:

  • What can you help me with?
  • What is the difference between Basic, Standard, and Signature support tiers?
  • How long does Cisco keep my data in Cisco IQ?
  • What deployment options does Cisco IQ support?
  • Does Cisco IQ cost extra?
  • Does Cisco use my data to train its AI models?