Cisco LogoCisco Secure Network Analytics
Customer Success Metrics Configuration Guide 7.5.3Cisco Secure Network Analytics

Overview

Customer Success Metrics enables Cisco Secure Network Analytics (formerly Stealth watch) data to be sent to the cloud so that we can access vital information regarding the deployment, health, performance, and usage of your system.

  • Enabled: Customer Success Metrics is automatically enabled on your Secure Network Analytics appliances.
  • Internet Access: Internet access is required for Customer Success Metrics.
  • Cisco Security Service Exchange: Cisco Security Service Exchange is enabled automatically in v7.5.x and is required for Customer Success Metrics.
  • Data Files: Secure Network Analytics generates a JSON file with the metrics data.
    The data is deleted from the appliance immediately after it is sent to the cloud.

This guide includes the following information:

  • Configuring the Firewall: Configure your network firewall to allow communication from your appliances to the cloud. Refer to Configuring the Network Firewall.
  • Disabling Customer Success Metrics: To opt out of Customer Success Metrics, refer to Disabling Customer Success Metrics.
  • Customer Success Metrics: For details about the metrics, refer to Customer Success Metrics Data.

Cisco Secure Network Analytics -Icon For information on data retention and how to request deletion of usage metrics collected by Cisco, refer to Cisco Secure Network Analytics Privacy Data Sheet.
For assistance, please contact Cisco Support.

Configuring the Network Firewall

To allow communication from your appliances to the cloud, configure your network firewall on your Cisco Secure Network Analytics Manager (formerly Stealth watch Management Console).
Cisco Secure Network Analytics -Icon Make sure your appliances have Internet access.
Configuring the Manager
Configure your network firewall to allow communication from your Managers to the following IP addresses and port 443:

Cisco Secure Network Analytics -Icon If public DNS is not allowed, make sure you configure the resolution locally on your Managers.

Disabling Customer Success Metrics

Use the following instructions to disable Customer Success Metrics on an appliance.

  1. Log in to your Manager.
  2. Select Configure > Global> Central Management.
  3. Click the
    (Ellipsis) icon for the appliance. Choose Edit Appliance Configuration.
  4. Click the General tab.
  5. Scroll to the External Services section.
  6. Uncheck the Enable Customer Success Metrics check box.
  7. Click Apply Settings.
  8. Follow the on-screen prompts to save your changes.
  9. On the Central Management Inventory tab, confirm the Appliance Status returns to Connected.
  10. To disable Customer Success Metrics on another appliance, repeat steps 3 through 9.

Customer Success Metrics Data

When Customer Success Metrics is enabled, the metrics are collected in the system and uploaded every 24 hours to the cloud. The data is deleted from the appliance immediately after it is sent to the cloud.
We do not collect identification data such as host groups, IP addresses, user names, or passwords.
Cisco Secure Network Analytics -Icon For information on data retention and how to request deletion of usage metrics collected by Cisco, refer to Cisco Secure Network Analytics Privacy Data Sheet.

Collection Types
Each metric is collected as one of the following collection types:

  • App Start: One entry every 1 minute (collects all the data since the application started).
  • Cumulative: One entry for a 24-hour period
  • Interval: One entry every 5 minutes (total of 288 entries per 24-hour period)
  • Snapshot: One entry for the point in time the report is generated

Cisco Secure Network Analytics -Icon Some of the collection types are collected at different frequencies than the defaults we’ve described here, or they may be configured (depending on the application). Refer to Metrics Details for more information.

Metrics Details
We’ve listed the collected data by appliance type. Use Ctrl + F to search the tables by keyword.

Flow Collector

Metric IdentificationDescriptionCollection Type
devices_cache.activeNumber of active MAC addresses from ISE in the devices cache.Snapshot
devices_ cache.deletedNumber of deleted MAC addresses from ISE in the devices cache because they have timed out.Cumulative
devices_ cache.droppedNumber of dropped MAC addresses from ISE because the devices cache is full.Cumulative
devices_cache.newNumber of new MAC addresses from ISE added into the devices cache.Cumulative
flow_stats.fpsOutbound flows per second in the last minute.Interval
flow_stats.flowsInbound flows processed.Interval
flow_cache.activeNumber of active flows in the Flow Collector flow cache.Snapshot
flow_cache.droppedNumber of flows dropped because the Flow Collector flow cache is full.Cumulative
flow_cache.endedNumber of flows ended in the Flow Collector flow cache.Interval
flow_cache.maxMaximum size of the Flow Collector flow cache.Interval
flow_ cache.percentagePercent of capacity of the Flow Collector flow cacheInterval
flow_cache.startedNumber of flows added to the Flow Collector flow cache.Cumulative
hosts_cache.cachedNumber of hosts in the host cache.Interval
hosts_cache.deletedNumber of hosts deleted in the host cache.Cumulative
hosts_cache.droppedNumber of hosts dropped because the host cache is full.Cumulative
hosts_cache.maxMaximum size of the host cache.Interval
hosts_cache.newNumber of new hosts added into the host cache.Cumulative
hosts_ cache.percentagePercent of capacity of the host cache.Interval
hosts_ cache.probationary_ deletedNumber of probationary hosts* deleted in the hosts cache.
*Probationary hosts are hosts that have never been the source of packets and bytes. These hosts are deleted first when clearing up space in the host cache.
Cumulative
interfaces.fpsOutbound number of interface statistics per second exported to Vertica.Interval
security_events_ cache.activeNumber of active security events in the security events cache.Snapshot
security_events_ cache.droppedNumber of security events dropped because the security events cache is full.Cumulative
security_events_ cache.endedNumber of ended security events in the security events cache.Cumulative
security_events_ cache.insertedNumber of security events inserted into the database table.Interval
security_events_ cache.maxMaximum size of the security events cache.Interval
security_events_ cache.percentagePercent of capacity of the security events cache.Interval
security_events_ cache.startedNumber of started security events in the security events cache.Cumulative
session_cache.activeNumber of active sessions from ISE in the session cache.Snapshot
session_ cache.deletedNumber of deleted sessions from ISE in the session cache.Cumulative
session_ cache.droppedNumber of sessions from ISE dropped because the sessions cache is full.Cumulative
session_cache.newNumber of new sessions from ISE added into the session cache.Cumulative
users_cache.activeNumber of active users in the users cache.Snapshot
users_cache.deletedNumber of deleted users in the users cache because they have timed out.Cumulative
users_cache.droppedNumber of users dropped because the users cache is full.Cumulative
users_cache.newNumber of new users in the users cache.Cumulative
reset hourFlow Collector reset hour.N/A
vertica_stats.query_ duration_sec_minMaximum query response time.Cumulative
vertica_stats.query_ duration_sec_minMinimum query response time.Cumulative
vertica_stats.query_ duration_sec_avgAverage query response time.Cumulative
exporters.fc_countNumber of exporters per Flow Collector.Interval

FlowCollector StatsD

Metric IdentificationDescriptionCollection Type
ndr- agent.unprocessable_ findingNumber of NDR findings deemed unprocessable.Cumulative cleared daily
ndr-agent.ownership_ registration_failedTechnical detail: Number of certain kind of errors that happened during NDR finding processing.Cumulative cleared daily
ndr-agent.upload_ successNumber of NDR findings successfully processed by the agent.Cumulative cleared daily
ndr-agent.upload_ failureNumber of NDR findings unsuccessfully uploaded by the agent.Cumulative cleared daily
ndr-agent.processing_ failureNumber of failures observed during NDR processing.Cumulative cleared daily
ndr-agent.processing_ successNumber of successfully processed NDR findings.Cumulative cleared daily
ndr-agent.old_file_ deleteNumber of files deleted due to being too old.Cumulative cleared daily
ndr-agent.old_ registration_deleteNumber of ownership registrations revoked due to being too old.Cumulative cleared daily
netflowTotal NetFlow records from all Netflow exporters. Includes NVM records.Cumulative cleared daily
fs_netflowNetflow records received from Flow Sensors only.Cumulative cleared daily
netflow_bytesTotal NetFlow bytes received from any NetFlow exporter. Includes NVM records.Cumulative cleared daily
fs_netflow_bytesNetFlow bytes received from Flow Sensors only.Cumulative cleared daily
sflowsFlow records received from any sFlow exporter.Cumulative cleared daily
sflow_bytessFlow bytes received from any sFlow exporter.Cumulative cleared daily
nvm_endpointUnique NVM endpoints seen today (before daily reset).Cumulative cleared daily
nvm_bytesNVM bytes received (including flow, endpoint, and endpoint_interface records).Cumulative cleared daily
nvm_netflowNVM bytes received (including flow, endpoint, and endpoint_interface records).Cumulative cleared daily
all_sal_eventAll Security Analytics and Logging (OnPrem) events received (including Adaptive Security Appliance and non-Adaptive Security Appliance), counted by number of events received.Cumulative cleared daily
all_sal_bytesAll Security Analytics and Logging (OnPrem)Cumulative
events received (including Adaptive Security Appliance and non-Adaptive Security Appliance, counted by number of bytes received.cleared daily
ftd_sal_eventSecurity Analytics and Logging (OnPrem) (non-Adaptive Security Appliance) events received from Firepower Threat Defense/NGIPS devices only.Cumulative cleared daily
ftd_sal_bytesSecurity Analytics and Logging (OnPrem) (non-Adaptive Security Appliance) bytes received from Firepower Threat Defense/NGIPS devices only.Cumulative cleared daily
ftd_lina_bytesData Plane bytes received from Firepower Threat Defense devices only.Cumulative cleared daily
ftd_lina_eventData Plane events received from Firepower Threat Defense devices only.Cumulative cleared daily
asa_asa_eventAdaptive Security Appliance events received from Adaptive Security Appliance devices only.Cumulative cleared daily
asa_asa_bytesASA bytes received from Adaptive Security Appliance devices only.Cumulative cleared daily

Manager

Metric IdentificationDescriptionCollection Type
exporter_cleaner_ cleaning_enabledIndicates whether the Inactive Interfaces and Exporters Cleaner is enabled.Snapshot
exporter_cleaner_ inactive_thresholdNumber of hours an exporter can be inactive before it is removed.Snapshot
exporter_cleaner_ using_legacy_cleanerIndicates whether the Cleaner should use the legacy cleaning functionality.Snapshot
exporter_cleaner_ hours_after_resetNumber of hours after reset that a domain should be cleaned.Snapshot
exporter_cleaner_ interface_without_ status_presumed_ staleIndicates whether the Cleaner removes interfaces that were unknown to a Flow Collector at the last reset hour, treating them as inactive.Snapshot
ndrcoordinator.files_ uploadedIndicates whether Secure Network Analytics deployment works as Data Store.Snapshot
report_completeName of the report and the run-time in milliseconds (Manager only).N/A
report_paramsFilters used when the Manager queries the Flow Collector databases.
Data exported per query:
maximum number of rows
include-interface-data flag
fast-query flag
exclude-counts flag
flows direction filters
order-by column
default-columns flag
Time window start date and time
Time window end date and time
Number of device ids criteria
Number of interface ids criteria
Number of IPs criteria
Number of IP ranges criteria
Number of hostgroups criteria
Number of hosts pairs criteria
Whether results are filtered by MAC addresses
Whether results are filtered by TCP/UDP ports
Number of user names criteria
Whether results are filtered by number of bytes/packets
Whether results are filtered by total number of bytes/packets
Whether results are filtered by URL
Whether results are filtered by protocols
Whether results are filtered by applications ids
Whether results are filtered by process name
Whether results are filtered by process hash
Whether results are filtered by TLS version
Number of ciphers in cipher suite criteria
Snapshot
Frequency: Per Request
domain.integration_ ad_countNumber of AD connections.Cumulative
domain.rpe_countNumber of role policies configured.Cumulative
domain.hg_changes_ countChanges to the Host Group configuration.Cumulative
integration_snmpSNMP agent usage.N/A
integration_cognitiveGlobal threat alerts (formerly Cognitive Intelligence) integration enabled.N/A
domain.servicesNumber of services defined.Snapshot
applications_default_ countNumber of applications defined.Snapshot
smc_users_countNumber of users in the Web App.Snapshot
login_api_countNumber of API log ins.Cumulative
login_ui_countNumber of Web App log ins.Cumulative
report_concurrencyNumber of reports running concurrently.Cumulative
apicall_ui_countNumber of Manager API calls using the Web App.Cumulative
apicall_api_countNumber of Manager API calls using the API.Cumulative
ctr.enabledCisco SecureX threat response(formerly Cisco Threat Response) integration enabled.N/A
ctr.alarm_sender_ enabledSecure Network Analytics alarms to SecureX threat response enabled.N/A
ctr.alarm_sender_ minimal_severityMinimal severity of alarms sent to SecureX threat response.N/A
ctr.enrichment_ enabledEnrichment request from SecureX threat response enabled.N/A
ctr.enrichment_limitNumber of top Security Events to be returned to SecureX threat response.Cumulative
ctr.enrichment_periodTime period for Security Events to be returned to SecureX threat response.Cumulative
ctr.number_of_ enrichment_requestsNumber of enrichment requests received from SecureX threat response.Cumulative
ctr.number_of_refer_ requestsNumber of requests for Manager pivot link received from SecureX threat response.Cumulative
ctr.xdr_number_of_ alarmsDaily count of alarms sent to XDR.Cumulative
ctr.xdr_number_of_ alertsDaily count of alerts sent to XDR.Cumulative
ctr.xdr_sender_ enabledTrue/False if sending is enabled.Snapshot
failover_roleManager primary or secondary failover role in the cluster.N/A
domain.cse_countNumber of custom security events for a domain ID.Snapshot

Manager StatsD

Metric IdentificationDescriptionCollection Type
ndrcoordinator.analytics_ enabledMarks whether Analytics is enabled. 1 if yes, 0 if no.Snapshot
ndrcoordinator.agents_ contactedNumber of NDR agents contacted during the last contact.Snapshot
ndrcoordinator.processing_ errorsNumber of errors during NDR finding processing.Cumulative
ndrcoordinator.files_ uploadedNumber of NDR findings uploaded for processing.Cumulative
ndrevents.processing_errorsNumber of files failed to process because the system did not deliver the finding or could not parse the request.Cumulative
ndrevents.files_uploadedNumber of files that were sent to NDR events for processing.Cumulative
sna_swing_client_aliveInternal counter of API calls used by SNA Manager Desktop client.Snapshot
swrm_is_in_useResponse Management: Value is 1 if Response Management is used. Value is 0 if it is not used.Snapshot
swrm_rulesResponse Management: Number of custom rules.Snapshot
swrm_action_emailResponse Management: Number of custom actions of Email type.Snapshot
swrm_action_syslog_ messageResponse Management: Number of custom actions of Syslog Message type.Snapshot
swrm_action_snmp_trapResponse Management: Number of custom actions of SNMP Trap type.Snapshot
swrm_action_ise_ancResponse Management: Number of custom actions of ISE ANC Policy type.Snapshot
swrm_action_webhookResponse Management: Number of custom actions of Webhook type.Snapshot
swrm_action_ctrResponse Management: Number of custom actions of threat response Incident type.Snapshot
va_ctVisibility Assessment: Calculated run- time in milliseconds.Snapshot
va_ceVisibility Assessment: Number of errors (when calculation crashes).Snapshot
va_hcsVisibility Assessment: Host count API response size in bytes (detect excessive response size).Snapshot
va_ssVisibility Assessment: Scanners API response size in bytes (detect excessive response size).Snapshot
va_sesVisibility Assessment: Security Events API response size in bytes (detect excessive response size).Snapshot
sal_input_sizeNumber of entries in the pipeline input queue.Snapshot Frequency: 1 minute
sal_completed_sizeNumber of entries in the completed batch queue.Snapshot Frequency: 1 minute
sal_flush_timeAmount of time in milliseconds since the last pipeline flush.
Available with Security Analytics and Logging (OnPrem) Single-node only.
Snapshot Frequency: 1 minute
sal_batches_succeededNumber of batches successfully written to the file.
Available with Security Analytics and Logging (OnPrem) Single-node only.
Interval Frequency: 1 minute
sal_batches_processedNumber of batches that were processed.
Available with Security Analytics and Logging (OnPrem) Single-node only.
Interval Frequency: 1 minute
sal_batches_failedNumber of batches that have failed to complete writing to the file.
Available with Security Analytics and Logging (OnPrem) Single-node only.
Interval Frequency: 1 minute
sal_files_movedNumber of files moved to the ready directory.
Available with Security Analytics and Logging (OnPrem) Single-node only.
Interval Frequency: 1 minute
sal_files_failedNumber of files that have failed to be moved.
Available with Security Analytics and Logging (OnPrem) Single-node only.
Interval Frequency: 1 minute
sal_files_discardedNumber of files discarded due to error.
Available with Security Analytics and Logging (OnPrem) Single-node only.
Interval Frequency: 1 minute
sal_rows_writtenNumber of rows written to the referenced file.
Available with Security Analytics and Logging (OnPrem) Single-node only.
Interval Frequency: 1 minute
sal_rows_processedNumber of rows that were processed.
Available with Security Analytics and Logging (OnPrem) Single-node only.
Interval Frequency: 1 minute
sal_rows_failedNumber of rows that failed to be written. Available with Security Analytics andInterval Frequency:
sal_total_batches_ succeededTotal number of batches successfully written to the file.
Available with Security Analytics and Logging (OnPrem) Single-node only.
App Start Frequency: 1 minute
sal_total_batches_ processedTotal number of batches that were processed.
Available with Security Analytics and Logging (OnPrem) Single-node only.
App Start Frequency: 1 minute
sal_total_batches_failedTotal number of files that have failed to complete writing to the file.
Available with Security Analytics and Logging (OnPrem) Single-node only.
App Start Frequency: 1 minute
sal_total_files_movedTotal number of files moved to the ready directory.
Available with Security Analytics and Logging (OnPrem) Single-node only.
App Start Frequency: 1 minute
sal_total_files_failedTotal number of files that have failed to be moved.
Available with Security Analytics and Logging (OnPrem) Single-node only.
App Start Frequency: 1 minute
sal_total_files_discardedTotal number of files discarded due to error.
Available with Security Analytics and Logging (OnPrem) Single-node only.
App Start Frequency: 1 minute
sal_total_rows_writtenTotal number of rows written to the referenced file. Available with Security Analytics andApp Start Frequency: 1 minute
Logging (OnPrem) Single-node only.
sal_total_rows_processedTotal number of rows that were processed.
Available with Security Analytics and Logging (OnPrem) Single-node only.
App Start Frequency: 1 minute
sal_total_rows_failedTotal number of rows that failed to be written.
Available with Security Analytics and Logging (OnPrem) Single-node only.
App Start Frequency: 1 minute
sal_transformer_<transformer id>Number of transformation errors in this transformer.
Available with Security Analytics and Logging (OnPrem) Single-node only.
Interval Frequency: 1 minute
sal_bytes_per_eventAverage number of bytes per event received.Interval Frequency: 1 minute
sal_bytes_receivedNumber of bytes received from the UDP server.Interval Frequency: 1 minute
sal_events_receivedNumber of events received from the UDP server.Interval Frequency: 1 minute
sal_total_events_receivedTotal number of events received by the router.App Start
sal_events_droppedNumber of unparsable events dropped.Interval Frequency: 1 minute
sal_total_events_droppedTotal number of unparsable events dropped.App Start Frequency: 1 minute
sal_events_ignoredNumber of ignored/unsupported events.Interval Frequency: 1 minute
sal_total_events_ignoredTotal number of ignored/unsupported events.App Start Frequency: 1 minute
sal_receive_queue_sizeNumber of events in the receive queue.Snapshot Frequency: 1 minute
sal_events_per secondIngest rate (events per second).Interval Frequency: 1 minute
sal_bytes_per_secondIngest rate (bytes per second).Interval Frequency: 1 minute
sna_trustsec_report_runsNumber of daily TrustSec report requests.Cumulative

UDP Director

Metric IdentificationDescriptionCollection Type
sources_countNumber of sources.Snapshot
rules_countNumber of rules.Snapshot
packets_unmatchedMaximum unmatched packets.Snapshot
packets_droppedDropped packets eth0.Snapshot

All Appliances

Metric IdentificationDescriptionCollection Type
plat formHardware platform (ex: Dell 13G, KVM Virtual Platform).N/A
serialSerial number of the appliance.N/A
versionSecure Network Analytics version number (ex: 7.1.0).N/A
version_buildBuild number (ex: 2018.07.16.2249-0).N/A
version_patchPatch number.N/A
csm_versionCustomer Success Metrics code version (ex: 1.0.24-SNAPSHOT).N/A
power_supply.statusManager and Flow Collector power supply statistics.Snapshot
productInstanceNameSmart Licensing product identifier.N/A

Contacting Support

If you need technical support, please do one of the following:

Change History

Document Version Published Date Description
1_0August 18, 2025Initial Version.

Copyright Information
Cisco and the Cisco logo are trademarks or registered trademarks of Cisco and/or its affiliates in the U.S. and other countries. To view a list of Cisco trademarks, go to this URL: https://www.cisco.com/go/trademarks. Third-party trademarks mentioned are the property of their respective owners. The use of the word partner does not imply a partnership relationship between Cisco and any other company. (1721R)

© 2025 Cisco Systems, Inc. and/or its affiliates.
All rights reserved.

Documents / Resources

Cisco Secure Network Analytics [pdf] User Guide
v7.5.3, Secure Network Analytics, Secure Network Analytics, Network Analytics, Analytics
CISCO Secure Network Analytics [pdf] User Guide
UCS C-Series M5, Manager 2210, Data Node 6200, Flow Collector 4210, Flow Collector 5210, Engine Flow Collector 5210 Database, Flow Sensor 1210, Flow Sensor 3210, Flow Sensor 4210, Flow Sensor 4240, UDP Director 2210, Secure Network Analytics, Network Analytics, Analytics
CISCO Secure Network Analytics [pdf] User Guide
UCS C-Series M6, Manager 2210, Data Node 6200, Flow Collector 4210, Flow Collector 5210, Engine Flow Collector 5210 Database, Flow Sensor 1210, Flow Sensor 3210, Flow Sensor 4210, Flow Sensor 4240, UDP Director 2210, Secure Network Analytics, Network Analytics, Analytics
cisco Secure Network Analytics [pdf] User Guide
Secure Network Analytics, Network Analytics, Analytics
cisco Secure Network Analytics [pdf] User Guide
7.5.3, DV 1.0, Secure Network Analytics, Network Analytics, Analytics
cisco Secure Network Analytics [pdf] User Guide
v7.5.3, Secure Network Analytics, Network Analytics, Analytics
CISCO Secure Network Analytics [pdf] User Guide
v7.5.3, Secure Network Analytics, Network Analytics, Analytics
CISCO Secure Network Analytics [pdf] Instruction Manual
v7.5.3, Secure Network Analytics, Network Analytics, Analytics
CISCO Secure Network Analytics [pdf] User Guide
v7.5.3, Secure Network Analytics, Network Analytics, Analytics

References

Leave a comment

Your email address will not be published. Required fields are marked *