Cisco Security Cloud Control: Secure Firewall ASA Management

PDF

Cisco Security Cloud Control: Secure Firewall ASA Management

Cisco Secure Cloud Analytics alerts from Security Cloud Control

Want to summarize with AI?

Log in

Describes how to view Cisco Secure Cloud Analytics alerts from Security Cloud Control, including symptoms, checks, likely causes, and corrective actions for managed devices.


Cisco Secure Cloud Analytics alerts from Security Cloud Control are security notifications that

  • are generated from firewall event data and network flow data

  • require cross-launching from Security Cloud Control to the Secure Cloud Analytics portal for review, and

  • display in the Security Analytics menu with a badge showing the number of open alerts.

License requirements and access methods

Required License: Logging Analytics and Detection or Total Network Analytics and Monitoring

While you can review your firewall events on the Events logging page, you cannot review Cisco Secure Cloud Analytics alerts from the Security Cloud Control portal UI. You can cross-launch from Security Cloud Control to the Secure Cloud Analytics portal using the Security Analytics menu option, and view alerts generated from firewall event data (and from network flow data if you enabled Total Network Analytics and Monitoring). The Security Analytics menu option displays a badge with the number of Secure Cloud Analytics alerts in an open workflow status, if 1 or more are open.

If you use a Security Analytics and Logging license to generate Secure Cloud Analytics alerts, and you provisioned a new Secure Cloud Analytics portal, log into Security Cloud Control, then cross-launch to Secure Cloud Analytics using Cisco Security Cloud Sign On. You can also directly access your Secure Cloud Analytics portal through its URL.

See Cisco Security Cloud Sign On for more information.


Invite users to join your secure cloud analytics portal

Invite other users by email to join your Secure Cloud Analytics portal and enable them to create Cisco Security Cloud Sign On credentials for cross-launch access from Security Cloud Control to Secure Cloud Analytics.

The initial user to request the Secure Cloud Analytics portal provision has administrator privileges in the Secure Cloud Analytics portal. That user can invite other users by email to join the portal. If these users do not have Cisco Security Cloud Sign On credentials, they can create them using the link in the invite email. Users can then use Cisco Security Cloud Sign On credentials to log in during the cross-launch from Security Cloud Control to Secure Cloud Analytics.

Before you begin

Follow these steps to invite other users to your Secure Cloud Analytics portal by email:

Procedure

1.

Log into your Secure Cloud Analytics portal as an administrator.

2.

Select Settings > Account Management > User Management.

3.

Enter an Email address.

4.

Click Invite.

The invited user receives an email invitation to join the Secure Cloud Analytics portal and can create Cisco Security Cloud Sign On credentials if needed.


Cross-launch from Security Cloud Control to Secure Cloud Analytics

This task enables you to access and view security alerts through the integrated interface between Security Cloud Control and Secure Cloud Analytics.

To view security alerts from Security Cloud Control:

Procedure

1.

Log into the Security Cloud Control portal.

2.

In the left pane, choose Analytics > Secure Cloud Analytics.

3.

In the Secure Cloud Analytics interface, select Monitor > Alerts.

You can now view and monitor security alerts from the Secure Cloud Analytics interface.