Outlines the procedures and features for maintaining and monitoring Cisco Cyber Vision, including baseline management, system operations, syslog and telemetry configuration, update processes, certificate and extension management, threat detection, and risk scoring capabilities.
Monitored presets
Explains how monitored presets and baselines in Cisco Cyber Vision Center help you monitor defined subsets of network data and detect network deviations.
Center shutdown/reboot
Introduces the Cisco Cyber Vision capability to safely shut down or reboot Center, including an appropriate use case for rebooting.
Upgrade with a combined update file
Guides you through downloading, validating, and applying a Cisco Cyber Vision combined update file to the Center and applicable sensors.
Syslog configurations
Introduces syslog configurations for forwarding Cisco Cyber Vision events and alerts to external syslog servers.
Database import and export
Describes the process for importing and exporting the Cisco Cyber Vision database via the System interface. This functionality enables users to back up industrial network data or transfer databases between centers.
Update the Knowledge DB
Guides you to download and import the latest Knowledge DB so that Cisco Cyber Vision can recognize current vulnerabilities, icons, and threats.
Certificate fingerprints
Introduces certificate fingerprints, explaining their role in identifying and verifying certificates, enabling secure communication between Global Centers and synchronized Centers, and outlining best practices for enrollment, renewal, and maintaining secure connectivity.
Disable Cisco Cyber Vision telemetry
Guides you through turning off the default feature that collects anonymous diagnostics and usage data to help Cisco understand and enhance product usage.
Reset to Factory Defaults
Describes the process and impact of restoring system settings to their original state. This action serves as a final troubleshooting measure when other recovery methods fail.
Snort
Introduces Snort as a network intrusion detection system that analyzes traffic using rules, integrates with Cisco Cyber Vision for real-time alerts, outlines device availability, and describes management and configuration options on Center DPI interfaces.
Risk Score
Provides configuration options for the time range used in risk score computation. This setting determines the historical activity window analyzed during the hourly calculation process.
Cisco Cyber Vision extensions
Introduces optional add-ons for Cisco Cyber Vision Center that provide features for device management, detection, and integration with external services.