This document describes how to recover a deleted default host group by restoring the correct host-group ID in Cisco Secure Network Analytics.
When default host group is deleted and a new host group created using the same name to 'replace' the deleted original, the new host group uses a custom ID instead of the default ID.
Features that require specific default host groups to function, such as the Host Classifier application, fail to detect the 'replacement' host group.
Default host groups use two-digit IDs, for example 28 or 30 and user created host groups are considered to be custom and use five-digit IDs, for example 50081.
If a default host group is deleted and then recreated as a custom host group, the recreated group receives a five-digit ID.
Some features can fail because of this and to correct the problem, the host-group ID must match the default value.
If you have a backup of the host_groups.xml file from before the deletion, you can restore the deleted default host group by importing the backup file through the Secure Network Analytics Manager interface.
If you want to restore only a specific default host group or a subtree without overwriting other custom host groups, complete these detailed steps:
Create a Temporary Domain
Export the Specific Default Host Group or Subtree
Delete the Temporary Domain
Import the Exported Host Group or Subtree into the Correct Tree/Subtree
Confirm the Imported Host Group Uses the a Default Two-Digit ID
Verify Host Classifier Application Detection
If none of these resolve the issue, or if you have questions, please contact Cisco TAC for further assistance.
Recreating a deleted default host group manually results in the system assigning a five-digit custom ID. The Host Classifier application expects the original two-digit ID; when it fails to match, the application cannot detect or classify the host group.
API Cisco DevNet
Open a TAC Case
| Revision | Publish Date | Comments |
|---|---|---|
1.0 |
30-Aug-2022
|
Initial Release |