Cisco Cyber Vision Classic UI Administration Guide, Release 5.6.0

PDF

Cisco Cyber Vision Classic UI Administration Guide, Release 5.6.0

Monitored presets

Want to summarize with AI?

Log in

Explains how monitored presets and baselines in Cisco Cyber Vision Center help you monitor defined subsets of network data and detect network deviations.


A monitored preset is a preset that is monitored against a baseline. To monitor your network using Cisco Cyber Vision Center, you must set up monitored presets.

On the Explore page, you can select a preset to view the network data that matches the preset definition. You can also export the data as a PDF file.

Presets

A preset is a customizable view that allows you to focus on specific subsets of network data. A preset filters network data based on defined criteria and gives you a focused view of an organizational network for quick, meaningful analysis.

The parameters that you can configure for a preset include:

  • Time

  • Risk score range

  • Networks, by IP subnets or VLAN IDs

  • Device tags

  • Activity tags

  • Groups

  • Sensors

Baselines

A baseline is a snapshot of a preset. It is the reference point against which network behavior is periodically compared to detect network deviations or anomalies, such as new devices, altered communications, or unusual activities that may indicate security issues or operational problems.

Multiple baselines for a preset

You can create multiple baselines for a preset to monitor various known states of your network.

For example, network activity baselines may differ for weekdays and weekends. Create two baselines for these scenarios, and activate the baseline that accurately monitors your network on any given day.

To activate one of multiple baselines for a monitored preset, refer to Configure monitored presets.


Create a baseline

Establish a baseline for a preset to monitor and track network activity in Cisco Cyber Vision Center.

Follow these steps to create a baseline for a preset.

Procedure

  1. From the main menu, select Explore.

  2. Select the Create baseline icon for a preset from one of the following locations:

    • The preset dashlet listed on the Explore page.

    • The preset details page displayed when you select a preset dashlet.

  3. Enter a name and description for the preset.

  4. Click Create.

The baseline is created. You can view it from the Monitor page in Cisco Cyber Vision Center, where all available baselines are displayed and categorized by their respective presets.


Configure monitored presets

Configure a monitored preset to define the interval for checking the network and the types of event differences for which you want to view alerts.

Any differences between the selected baseline and the current network status result in alerts that you can review and acknowledge.

Before you begin

A monitored preset is a preset with a baseline. Refer to Create a baseline.

Procedure

  1. From the main menu, select Monitor.

  2. For each monitored preset that you want to configure, click the vertical ellipsis, then select Monitored preset settings.

  3. Configure the monitored preset.

    1. Enter the monitoring interval in seconds.
    2. If you created more than one baseline for the preset, select the baseline that you want to activate in the Monitored baseline field.
    3. In the Events severity section, select the severity level for alerts generated for each event type.
    4. In the Advanced settings section, select the component, property, and activity differences for which you want to view alerts.
    5. Click OK.

Manage monitored preset differences

Acknowledge or report a single monitored preset difference entry.

Acknowledge an entry to mark a reported event as normal for the network. Report an entry to identify a reported event as an anomaly and create an event in Cisco Cyber Vision Center.

After you select a baseline on the Monitor page, you can use the following bulk-management options:

  • To acknowledge all differences across the components and activities, click the check mark in the left pane.

  • To acknowledge or report multiple, specific differences in the components or activities listings, select the entries and then select Acknowledge Selection or Report Selection.

Procedure

  1. From the main menu, select Monitor.

  2. In the What changed area, select the baseline that you want to examine for a monitored preset.

  3. View the reported differences.

    Differences are reported based on one of the following categories:

    • New components

    • New activities

  4. To view the communication flows that may have caused the reported difference, click an entry to view its details, and then click the Investigate with flows link.

  5. In the components list, click an entry to view its details.

    You can choose from the following four options:

    Table 1. Component actions

    Action

    Definition

    Acknowledge Component

    You can enter a message explaining your choice for reference. You have two acknowledgement options:

    • Acknowledge and include: Retain this alert and receive new alerts if something new happens with this component or activity.

    • Acknowledge and keep warning: Delete this alert and receive new alerts if the same event repeats.

    Ack. with related activities

    You can enter a message explaining your choice for reference.

    Select Acknowledge and include to retain the alert and receive alerts for any new events for the component and its activities.

    Report component

    You must enter a message explaining your choice for reference. You continue to receive alerts if the anomaly is detected again.

    Select Report component to create an event report for this anomaly.

    Show details

    View device tags and properties.

  6. In the activities list, click an entry to view its details.

    You can choose from the following three options:

    Table 2. Activity actions

    Action

    Definition

    Acknowledge activity

    Acknowledge the reported event as normal for the network. You can enter a message explaining your choice for reference. Two acknowledgement options are available:

    • Acknowledge and include: Retain this alert and receive alerts if something new happens with this component or activity.

    • Acknowledge and keep warning: Delete this alert and receive a new alert if the same event repeats.

    Report activity

    You must enter a message explaining your choice for reference. You continue to receive alerts if the anomaly is detected again.

    Select Report activity to create an event report for this anomaly.

    Show details

    View activity tags and variables.