Cisco Multicloud Defense User Guide

PDF

Cisco Multicloud Defense User Guide

Flow Analytics - All Events

Want to summarize with AI?

Log in

Find details about all network and security events in Flow Analytics, including session, application, policy, traffic, and threat information for investigation.


Flow Analytics - All Events provides overall visibility into network and security events from the entire Multicloud Defense solution.

Tables and Fields available in All Events are as follows:

Event Details

Description

Date and Time

ISO 8601 format: YYYY-MM-DD T HH:MM:SS:S Example: 2020-11-22T10:58:46.820.

Type

APPID, AV, DLP, DPI, FLOW_LOG, FQDNFILTER, L4_FW, L7DOS, MALICIOUS_SRC, SNI, TLS_ERROR, TLS_LOG, URLFILTER.

CSP Account

Multicloud Defense CSP Account.

Gateway

Multicloud Defense Gateway.

Region

Region of the Multicloud Defense Gateway.

Level

DEBUG, INFO, NOTICE, WARNING, ERROR, CRITICAL, ALERT, EMERGENCY.

Session ID

..

Service

Description

Src IP

Source IP Address.

Src Port

Source Port.

Dest IP

Destination IP Address.

Dest Port

Destination Port.

Protocol

UDP, TCP.

Application Info

Description

Client App Name

Application name associated with client side of the session. Example: Advanced Packaging Tool.

Payload App Name

HTTP application name associated with webserver host. Example: Facebook.

Service App Name

Application name associated with server side of the session. Example: HTTP.

Action

Description

Action

ALLOW, DENY.

State

ESTABLISHED, CLOSE, CLOSED, CLOSE_WAIT, TIME_WAIT, FIN_WAIT, LAST_ACK.

HTTP Request

Description

Host

Host portion of URL.

Method

GET, PUT, POST, HEAD, DELETE, PATCH, OPTIONS.

URI

URI Identifier RFC 3986.

Rule

Description

ID

ID number/description of Multicloud Defense Rule. Example 59 (egress-prod-apt-80).

FQDN

Description

FQDN

Fully Qualified Domain Name.

Category Name

Category classification of the FQDN. Example: Social Media.

Reputation

Reputation score of the FQDN.


Event Logs

Event logs contain details of all traffic that flows through the Multicloud Defense Gateway.

After inspection, Multicloud Defense generates sessions and events that are based on what is in the packet and what is defined in the policy. The analysis, related details of events, and actions that are taken are all captured in the form of logs, available under Investigate > Flow Analytics > All Events. The system retains these logs for 30 days.

Event types that the logs capture:

Table 1. Event Types and Descriptions

Event Type

Event Name

Description

FQDN FILTER

Fully Qualified Domain Name (FQDN) Filtering

The related logs generate with details of the FQDN, source, destination IP and so on. The FQDN filtering event only generates in case the policy has an FQDN filtering profile.

SNI

Server Name Indication (SNI)

SNI allows multiple host names to be served over HTTPS. This generates when Multicloud Defense observes the SNI in the TLS handshake.

APPID

App ID (APPID)

APPID logs generate when the event matches known applications in the database.

L4_FW

L4 Firewall

An L4 Firewall event generates when the event matches the policy in the ruleset.

URL FILTER

URL Filtering

URL filtering is used to filter out network traffic based on the URL. This event log generates when it matches the URL filtering profile.

IPS

Intrusion Prevention System (IPS)

An IPS event generates when the network traffic matches the IPS ruleset.

DLP

Data Loss Protection (DLP)

A DLP event generates when the network traffic matches the DLP profile that is configured. The logs record these incidents, along with details of transmission such as endpoint, domain, username, rules, source, destination, action taken, and so on.

WAF

Web Application Firewall

A WAF event generates when the network traffic matches the WAF profile that is configured.

AV

Antivirus (AV)

An AV event generates when the event matches an AV ruleset in the network traffic.

DPI

Deep Packet Inspection (DPI)

A DPI event generates when the network traffic matches a rule that has an advanced security configured.

MALICIOUS_SRC

Malicious Source

A Malicious Source generates when the network traffic matches a malicious IP.

TLS_ERROR

TLS Error

A TLS error generates when there is an error during the TLS handshake.

TLS_LOG

TLS Log

A TLS log generates when the network traffic uses TLS. This captures the TLS handshake information such as cipher suites and TLS version.