Monitored presets
To monitor your network using Cisco Cyber Vision Center, you must set up monitored presets. A monitored preset is any preset that is monitored against a baseline.
To view the presets in your Center, from the main menu, choose Explore. Click a preset to view the network data that matches the preset definition. You can also export the data as a PDF file.
Presets
A preset is a customizable view that allow you to focus on specific subsets of network data. A preset filters network data based on defined criteria and gives you a focused view of an organizational network for quick, meaningful analysis.
The parameters that you can configure for a preset include:
-
Time
-
Risk score range
-
Networks, by IP subnets or VLAN IDs
-
Device tags
-
Activity tags
-
Groups
-
Sensors
Baseline
A baseline is a snapshot of a preset. It is the reference point against which network behavior is periodically compared to detect network deviations or anomalies by identifying changes such as new devices, altered communications, or unusual activities that may indicate security issues or operational problems.
Multiple baselines for a preset
You can create multiple baselines for a preset to monitor in various known states of your network.
For example, network activity baselines may differ for weekdays and weekends. Create two baselines for these scenarios, and activate the baseline that would be an accurate monitor for your network on any given day.
To activate one of multiple baselines for a monitored preset, see Configure monitored presets
Default presets
Some presets categories are available by default. You can make changes to the default presets and save the modified settings as new copies, but you cannot modify the default presets.
Preset category |
Presets available |
---|---|
Basics |
|
Asset management |
|
Control systems management |
|
IT communication management |
|
Security |
|
Network management |
|
Create categories
Procedure
Step 1 |
From the main menu, choose Explore. |
Step 2 |
Click New Category. |
Step 3 |
Enter a name for the category. |
Step 4 |
(Optional) Select the presets you want to place in this category. |
Step 5 |
Click Create. |
What to do next
-
Click the edit button for the category.
-
In the Presets field, select the preset you want to add to the category.
Create presets
Procedure
Step 1 |
From the main menu, choose Explore. |
Step 2 |
Click New Preset. |
Step 3 |
To create a preset:
|
Step 4 |
Select the newly created preset from the Explore page. |
Step 5 |
In the left pane, define each criteria category. For each criteria parameter:
|
Step 6 |
Click Save. |
What to do next
-
Select all: Include all the criteria parameters available in your Center.
-
Reject all: Exclude all the criteria parameters available in your Center.
-
Default: Reset all the selections such that no parameter is included or excluded.
Create baselines
Procedure
Step 1 |
From the main menu, choose Explore. |
Step 2 |
To create a baseline, you can create a baseline from a preset icon (
|
Step 3 |
Enter a name and description for the preset. |
Step 4 |
Click Create. |
Configure monitored presets
Before you begin
A monitored preset is a preset with a baseline. See Create baselines.
In this task, you:
-
Define the interval for checking the network against a monitored preset
-
Choose the type of event differences you want to view alerts for
Any differences in the selected baseline and the current network status result in alerts that can review and acknowledge.
Procedure
Step 1 |
From the main menu, choose Monitor. |
Step 2 |
For the monitored presets you want to configure, click the vertical ellipsis icon and choose Monitored preset settings. |
Step 3 |
For the monitored preset:
|
Manage monitored preset differences
-
To mark a reported event as normal for the network, acknowledge the entry.
-
To identify a reported event as an anomaly and create an event in Cisco Cyber Vision Center, report the entry.
After you select a baseline in the Monitor page, you have two bulk management options:
-
To acknowledge all differences across the components and activities, click the blue tick icon in the left pane
-
To acknowledge or report multiple, specific differences in the components or activities listings, select the entries and click Acknowledge Selection or Report Selection.
Procedure
Step 1 |
From the main menu, choose Monitor. |
||||||||||
Step 2 |
In the What changed area, for a monitored preset, click the baseline you want to examine. |
||||||||||
Step 3 |
You can view the differences reported based on:
|
||||||||||
Step 4 |
To view the communication flows that may have caused the reported difference, click Investigate with flows. |
||||||||||
Step 5 |
In the components list, click an entry to view the details. You can choose from four options:
|
||||||||||
Step 6 |
In the activities list, click an entry to view the details. You can choose from three options:
|