Cisco Stealthwatch
Scalable visibility and security analytics.
- Category
- Analytics & SIEM
- Pack
- CiscoStealthwatch
Configuration parameters
- server_url — Server URL (required)
- credentials — User Credentials (required)
- insecure — Trust any certificate (not secure)
- proxy — Use system proxy settings
Commands (11)
- cisco-stealthwatch-get-tag — Gets a single host group (called tag in the API).
- cisco-stealthwatch-get-tag-hourly-traffic-report — Gets the hourly traffic summary of the byte count for a single host group (called tenant in the API).
- cisco-stealthwatch-get-top-alarming-tags — Gets the top alarming host groups (called tags on the API) for a specific domain (called tenant in the API).
- cisco-stealthwatch-list-security-events-initialize — Initializes the list of security events for a domain (called tenant on the API).
- cisco-stealthwatch-list-security-events-results — Lists the security events results. Use this command after the search job completes.
- cisco-stealthwatch-list-security-events-status — Lists the security events status.
- cisco-stealthwatch-list-tags — Lists the host groups (called tags in the API).
- cisco-stealthwatch-list-tenants — Lists all domains if no domain is specified or gets a specified domain (called tenant(s) in the API).
- cisco-stealthwatch-query-flows-initialize — Initializes the flow search based on specified arguments. Must provide a start time, time range, or start time and end time.
- cisco-stealthwatch-query-flows-results — Retrieves the flow search results. Use this command after the search job completes.
- cisco-stealthwatch-query-flows-status — Checks the flow search status.