Cisco Cyber Vision Classic UI Administration Guide, Release 5.6.0

PDF

Cisco Cyber Vision Classic UI Administration Guide, Release 5.6.0

Navigate through Cisco Cyber Vision

Want to summarize with AI?

Log in

Describes the GUI navigation components within Cisco Cyber Vision, including the home screen, monitoring tools, reporting features, and system management settings. This guide assists users in effectively accessing dashboards, event lists, and configuration options.



Home

The Home page is a dashboard interface that provides a high-level summary of network activity and centralized access to system management tools.

  • Operational Overview tab for protocol distribution and critical events.

  • Security Overview tab for vulnerability and risk score analysis.

  • Navigation bar for accessing core application modules.

Home Page Components and Navigation

The home page is organized into two main tabs that allow users to monitor the industrial network over the last month.

The following tabs are available for monitoring:

  • Operational Overview: Displays the Protocol distribution pie chart, a list of Most critical events , and Preset highlights .

    Click Edit favorite presets to change what displays. Select the check boxes of the presets and click Save.

    Figure 1. Operational Overview
  • Security Overview: Displays the Vulnerable devices per severities ring chart, the Devices by risk score ring chart, and lists for Most critical events , Events by category , and Preset highlights.

    Figure 2. Security Overview

The navigation bar provides access to the following main pages:

  • Explore : Shows the overview of all presets, by defaults or configured.

  • Reports : Shows the Reports page to export valuable information about the industrial network.

  • Events : Shows the Events page which contains graphics and a calendar of all events generated by .

  • Monitor : Shows the Monitor mode page to perform and automatize data comparisons of the industrial network.

  • Search : Shows the searching area to look for precise data in the industrial network.

  • Admin : Shows how to update the system, configure exports parameters, import and export the database, update the Knowledge DB and reset data and system settings.


Detail Panel

A Detail panel is a condensed view about a device, a component, a group of components or an activity's information without changing the background device list or a map.

  • Displays general information about the selected element.

  • Provides editing capabilities for device or component names and group membership.

  • Includes navigation buttons to access technical sheets and specific data categories.

Accessing and Using the Detail Panel

To access a detail panel, click a device, a component or an activity on the map or a list.

The detail panel layout includes the following components:

Figure 3. Detail Panel Interface
  • Upper portion (1) : Provides general information about the element.

  • Round button (2) : Opens the element's technical sheet with all relevant information.

  • Rectangular buttons(3) : Redirect to the corresponding information inside the technical sheet .


Technical sheets

A technical sheet is an interactive documentation view that

  • provides comprehensive information about a device, component, activity, or flow,

  • displays data differently based on the selected element, and

  • allows direct interaction or editing within the sheet.

Technical sheets offer a unified interface for accessing, managing, and viewing element-specific information in the application.

Access a technical sheet

View the full details of a device, component, or activity by opening its technical sheet.

The technical sheet provides an interactive summary and detailed tabs for each element selected within the application.

Follow these steps to access a technical sheet.

Procedure

  1. From the main menu, choose Explore.

  2. From the top navigation bar, click the drop-down arrow of All Presets and select All Data from the drop-down list.

  3. From the top navigation bar, click the drop-down arrow of the third filter and select Map from the drop-down list.

  4. Click the Technical sheet icon.

The technical sheet for the selected device, component, or activity opens, displaying the relevant information and interactive functions.


Tabs in a device technical sheet

The device technical sheet contains relevant information and interactive functions. In a device or a component's technical sheet, you can also edit the element's name, add/remove it to/from a group, and add custom properties.

The top box of the technical sheet recaps the information found in the Detail panel. The rectangular buttons on the right redirect to the corresponding information inside the technical sheet.

The middle portion of the technical sheet contains tabs that vary based on the selected element. For a Device , the following tabs are available:

  • Basics : Shows an element's properties, tags, and associated components.

  • Risk score : Provides overview and detailed views of the risk assessment.

  • Security : Displays component vulnerabilities and credentials.

  • Activity : Shows activity flows, Mini Map , and external communications .

  • Automation : Contains variable accesses.

Additional reference information is available for the following topics:


Access the mini map

Use this procedure to access the Mini Map.

The mini map is a visual representation restricted to a specific device or component and its activities.

Procedure

  1. From the main menu, select Explore.

  2. In the top navigation bar, click All Presets, and then select All Data from the drop-down list.

  3. In the top navigation bar, click the third filter, and then select Map from the drop-down list.

  4. Select a device from the map.

  5. Click Technical sheet in the Details panel.

  6. Click Activity.

  7. Select Show inner components to view an exploded view of the devices.

  8. Click any element in the Mini Map.

    The Detail panel opens, where you can access more information.


Reports

A report is an export of industrial network data from traffic captured and processed by Cisco Cyber Vision.

Reports can uncover important information, such as sensitive entry points and acknowledged vulnerabilities for status reports.

Install the Reports extension to use the Reports page. From instruction to install the extension, refer to Install an extension.

Report data and formats

You can create reports from a Preset (default data) in Cisco Cyber Vision or from a custom one.

Reports extensions include .docx and .pdf formats.

Customize reports

You can add a logo, such as your company's logo, to customize a report. Reports display the Cisco logo by default.

Use the table of contents menu to set which content appears in the report.


Create a report

Enable users to create custom reports, generate output, review results, and rerun or download reports as needed.

Before you begin

The Cyber Vision Reports Management extension and Cyber Vision Version must be the same to generate a report.

Only users with Reports write permission can create reports. Users with Reports read permission can download reports.

Follow these steps to create a report:

Procedure

  1. From the main menu, select Reports.

  2. Click Create and run a Report.

  3. Enter a report name in Name.

    Optionally, enter a description in Description.

  4. Select a report Type.

    The report types are:

    • Security Posture: An automated summary that captures all vulnerabilities, risky activities, and security events that Cisco Cyber Vision finds on the devices in the selected preset.

    • Remote Access: An automated summary that captures all Remote Access Gateways and Remote Access-related activities that Cisco Cyber Vision finds on the devices in the selected preset.

    • Device Inventory: An automated summary of devices, risk profiles, licensing requirements, and inventory distribution within the report scope.

  5. Optionally, add a Customer logo.

    The logo appears on the report.

    Note

    If you do not upload a customer logo, the default Cisco logo is used.

  6. Select a format in Format, and then click Next.

  7. Select a preset from Preset.

  8. In Table of content, select the check boxes for the sections and subsections that you want to appear in the report.

    Note

    The available sections and subsections vary according to the selected report type.

  9. Click Save and Run.

    The report appears with Status: Processing. When complete, the status changes to Success appears.

What to do next

After you generate the report, you can perform the following actions:

  • To view and download a report, go to Reports, select the report name, and access download links in the Details panel. Older versions are listed under Previous Reports.

  • To generate a new report, select … under the Actions column and chooseRun Again.


Events

An event is an activity, property, or change involving software or hardware components that helps you identify and track significant activities on the network.

Events include the following:

  • A wrong password entered on the GUI.

  • A new component connected to the network.

  • An anomaly detected in Monitor Mode.

  • A component detected as vulnerable.

The Events page is available to Admin and Product users. To access the Events page, go to Admin > Events from the main menu.

On the Events administration page, you can customize the severity of events. By default, changes apply only to future events. To apply new customized severities to past events, use Apply severity to existing events.

This action is irreversible and can take several minutes to complete.

Select Reset severity to default to reset the severity settings.

Use the toggle buttons to enable or disable Syslog export and Database storage.

These options are active by default. Make sure that syslog is configured before export.


Events dashboard

The Events dashboard is a dashboard that shows event doughnut and line charts.

Doughnut charts display color-coded event severity categories and percentages.

Doughnut charts present event numbers and percentages by category and severity.

Events dashboard filters

The Events dashboard can be accessed by selecting Events from the main menu. You can view the list of events for a category. For more information, refer to Events.

Use the filter in the top-right corner of the Events page to filter events by Day, Week, Month, or Year.

Use the arrows for specific dates.

Doughnut chart details

The doughnut chart opens in List view, filtered by the corresponding category and severity. This view lets you quickly access more event details.

Events graph

The Events graph appears at the bottom of the dashboard page.

Use the filter in the top-right corner to view data by Day, Week, Month, or Year.

Hover over event markers on the line chart to view event counts by category for specific dates. The Cisco Cyber Vision Operations, Inventory Events, and Security Events tabs provides additional details.


Access the event list

List is a chronological view in which you can view and search events.

Use the search bar to find events by MAC and IP addresses, component name, destination and source flow, severity, and category.

You can search events by Day, Week, Month, or Year. Use the arrows for exact dates.

Follow these steps to access event list.

Procedure

  1. From the main menu, choose Events > List.

  2. Click an event result to view more details about the event.

  3. When an event is related to sensors, click See Sensor Statistics for more details.

  4. When an event is related to a component or an activity, click see Technical Sheet for more details.


Monitor mode

The Monitor mode is a monitoring tool in Cisco Cyber Vision that detects changes inside industrial networks. It shows the evolution of a network's behaviors, predicted or not, based on presets.

Because a network architecture, such as a PLC, switch, or SCADA, is constant and its behaviors tend to be stable over time, an established and configured network is predictable.

However, some behaviors are unpredictable and can compromise a network's operation and security.

When a behavior occurs, normal or abnormal changes are noted as differences in the Monitor mode.

Monitor mode is particularly convenient for large networks because a preset shows a network fragment, and changes are highlighted and managed separately in the Monitor mode views.


Search is a page that enables you to find components among unstructured data. Components can be searched by name, custom name, IP, MAC, tag, and property value.

The Search page is available from the main menu. The search field accepts the content used for a search, and the Search control initiates the search.

Note

Devices are not available on this page yet.

The Save this search as a Preset control creates a preset from search results. Presets automatically update as new data is detected on the network.

When you hover over a component, the technical sheet (2) icon appears. The technical sheet provides access to advanced data about the component.


System statistics

A system statistic is a monitoring metric that

  • reflects the operational status of the Center and sensors,

  • allows administrators to track resource health and usage, and

  • enables early detection of service or network issues.

Table 1. Feature History Table

Feature

Release Information

Feature Description

PCAP capture on the Cyber Vision Center interface

Release 5.4.x

You can capture PCAP data directly from the Cyber Vision Center interface, in addition to sensor based capture.

Sensor collected data quality report

Release 5.4.x

Easily monitor the quality of your sensor statistics with the Status Overview page. See real-time details for each sensor. Stay informed and ensure your data is always reliable.


System health statuses

To view system health, click the System statistics icon on any Cisco Cyber Vision Center page.

The System Health page helps you:

  • Check if all background processes, such as services and extensions, are running correctly.

  • See if background queues that collect data from sensors are free of congestion.

Table 2. System health statuses

Status

Description

Service Status

  • Shows the status of Cyber Vision services and extensions.

  • The system regularly checks these components

  • If a service or extension is down, open the service status for more information.

  • Click Update to refresh the service status.

  • If a service is down, a warning banner appears. The banner links to this page and highlights the failed service in red.

Queue Status

  • Displays the status of monitored sensor queues.

  • If a monitored queue drops messages, check the queue status to investigate.

  • The system lists any congested queues so you can address performance issues.

  • If a service is down, a warning banner appears. The banner links to the page where the failed service is highlighted in red.


System statistics for Center and sensors

The System Statistics page displays

  • key operational data for both the Center and its sensors, and

  • helps you monitor system health and troubleshoot issues.

Table 3. System statistics charts

Chart

Applicability

Description

System Health

Center and sensors

Displays CPU, RAM, and disk usage statistics for each sensor. Minimum, maximum, and average values are shown. The table also shows current usage and hardware score to help you get support.

Captured Packets

Sensors

The chart shows the number of packets that the sensor captures on the industrial network interface in bytes per second. It also displays the number of dropped packets. When packet drops occur, this indicates that the sensor is overloaded and traffic is being lost.

Network Interfaces Bandwidth

Center and sensors

The line charts display bandwidth for Collection and Industrial network interfaces. Bytes received and sent per second by Center are shown in the charts.

  • Collection Network Interface: Data exchanged between Center and sensors.

  • Capture Network Interface: Data captured by the sensor on the industrial network through each port pair.

Note

Data sent to the Industrial network should be zero. If you detect outbound traffic, your sensor is not passive. Contact support immediately.

Disk I/O (B/s)

Center

Displays the Center hard disk usage in bytes per second.

Table 4. System statistics features

Name

Description

Generate diagnostic

  • Generates a file to help with troubleshooting and support.

    • For Sensor: Click Generate diagnostic; file downloads automatically once available.

    • For Center: Click Generate diagnostic—then, once ready, click Download Diagnostic to retrieve the file.

PCAP Capture

Use the PCAP Capture field on the Center page to capture packet data directly. See Generate a PCAP file

Compute scores

Click Compute scores on the Center page to initiate system performance measurement. This action generates a new score.


Sensor status overview

The Status Overview page displays statistics collected from each sensor, including Sensor Name, Product ID, Health Status, Components, Activities, Unicast Activities, and Sensor last reported time. Use these statistics to assess sensor operation and identify potential issues.

The statistics show data for all time periods. You cannot filter them by time range.

To view sensor statistics, choose System statistics > Sensors > Status overview.

The table presents common sensor issues that can occur during operation.

Table 5. Common sensor status issues

Issue

Description

Zeros everywhere (components and activities)

No data appears in the table, which means the sensor is not receiving traffic. The sensor cannot analyze packets or send information to the center.

Review the sensor’s monitoring setup to resolve this issue.

Zero unicast activities

If activities and components appear but no unicast activities are present, the sensor is not receiving properly mirrored traffic. The switch traffic mirroring (monitor session) may be misconfigured. The center DPI interface may also not be in promiscuous mode. In this case, the session captures only broadcast or multicast traffic.

Time mismatch

If the Sensor last reported time column does not closely match the actual date and time, a time synchronization issue may prevent Cyber Vision from displaying data accurately.


Generate a PCAP file

Collect network traffic data (PCAP files) from the Center interface. Use these files to diagnose and resolve communication, performance, or security issues.

Procedure

  1. From the main menu, choose System statistics > Center.

  2. Under PCAP Capture, select the desired network interface (such as eth0 for administration or eth1 for collection).

  3. Enter filter parameters to specify the network traffic you want to capture.

    Note

    Use tcpdump filter syntax with Berkeley Packet Filters (BPF) to narrow the capture to the packets you want.

  4. Start the capture.

    Note

    Only one PCAP capture can run at a time.

  5. When finished, stop the capture.

You can download the PCAP capture file.

What to do next

When the capture is complete, click Download to save the capture file. Analyze the downloaded PCAP file to troubleshoot issues.


Create your personal account

You must create your personal account in Cisco Cyber Vision Center.

Follow these steps to create your personal account.

Procedure

  1. In the user menu at the top right corner, click the drop-down arrow and select My Settings.

    The My Settings page appears.

  2. Under the General field, enter Firstname and Lastname.

  3. Under the Language field, select the radio button for your preferred interface language.

  4. Enter your password.

    Passwords must contain at least 6 characters and comply with the following rules:

    • Passwords must contain a lower case character: a-z.

    • Passwords must contain an upper case character: A-Z.

    • Passwords must contain a numeric character: 0-9.

    • Passwords cannot contain the user ID.

    • Passwords must contain a special character: ~!"#$%&’()*+,-./:;<=>?@[]^_{|}.

    Change your password regularly to ensure platform and industrial network security.

    Note

    Your email will be requested for login access.

  5. Select the Restore default parameters checkbox to restore interface notifications.

  6. Click Save settings.

  7. Clear application cookies.