Cisco Secure Network Analytics

Customer Success Metrics Configuration Guide 7.5.3

An image showing a modern data center with rows of server racks and cabinets, featuring a central aisle and closed white cabinets.

Overview

Customer Success Metrics enables Cisco Secure Network Analytics (formerly Stealthwatch) data to be sent to the cloud so that Cisco can access vital information regarding the deployment, health, performance, and usage of your system.

This guide includes the following information:

For information on data retention and how to request deletion of usage metrics collected by Cisco, refer to Cisco Secure Network Analytics Privacy Data Sheet.

For assistance, please contact Cisco Support.

Configuring the Network Firewall

To allow communication from your appliances to the cloud, configure your network firewall on your Cisco Secure Network Analytics Manager (formerly Stealthwatch Management Console).

Note: Make sure your appliances have Internet access.

Configuring the Manager

Configure your network firewall to allow communication from your Managers to the following IP addresses and port 443:

Note: If public DNS is not allowed, make sure you configure the resolution locally on your Managers.

Disabling Customer Success Metrics

Use the following instructions to disable Customer Success Metrics on an appliance.

  1. Log in to your Manager.
  2. Select Configure > Global > Central Management.
  3. Click the [...] (Ellipsis) icon for the appliance. Choose Edit Appliance Configuration.
  4. Click the General tab.
  5. Scroll to the External Services section.
  6. Uncheck the Enable Customer Success Metrics check box.
  7. Click Apply Settings.
  8. Follow the on-screen prompts to save your changes.
  9. On the Central Management Inventory tab, confirm the Appliance Status returns to Connected.
  10. To disable Customer Success Metrics on another appliance, repeat steps 3 through 9.

Customer Success Metrics Data

When Customer Success Metrics is enabled, the metrics are collected in the system and uploaded every 24 hours to the cloud. The data is deleted from the appliance immediately after it is sent to the cloud.

Cisco does not collect identification data such as host groups, IP addresses, user names, or passwords.

For information on data retention and how to request deletion of usage metrics collected by Cisco, refer to Cisco Secure Network Analytics Privacy Data Sheet.

Collection Types

Each metric is collected as one of the following collection types:

Some of the collection types are collected at different frequencies than the defaults described here, or they may be configured (depending on the application). Refer to Metrics Details for more information.

Metrics Details

The collected data is listed by appliance type. Use Ctrl + F to search the tables by keyword.

Flow Collector

Metric Identification Description Collection Type
devices_cache.activeNumber of active MAC addresses from ISE in the devices cache.Snapshot
devices_cache.deletedNumber of deleted MAC addresses from ISE in the devices cache because they have timed out.Cumulative
devices_cache.droppedNumber of dropped MAC addresses from ISE because the devices cache is full.Cumulative
devices_cache.newNumber of new MAC addresses from ISE added into the devices cache.Cumulative
flow_stats.fpsOutbound flows per second in the last minute.Interval
flow_stats.flowsInbound flows processed.Interval
flow_cache.activeNumber of active flows in the Flow Collector flow cache.Snapshot
flow_cache.droppedNumber of flows dropped because the Flow Collector flow cache is full.Cumulative
flow_cache.endedNumber of flows ended in the Flow Collector flow cache.Interval
flow_cache.maxMaximum size of the Flow Collector flow cache.Interval
flow_cache.percentagePercent of capacity of the Flow Collector flow cacheInterval
flow_cache.startedNumber of flows added to the Flow Collector flow cache.Cumulative
hosts_cache.cachedNumber of hosts in the host cache.Interval
Metric Identification Description Collection Type
hosts_cache.deletedNumber of hosts deleted in the host cache.Cumulative
hosts_cache.droppedNumber of hosts dropped because the host cache is full.Cumulative
hosts_cache.maxMaximum size of the host cache.Interval
hosts_cache.newNumber of new hosts added into the host cache.Cumulative
hosts_cache.percentagePercent of capacity of the host cache.Interval
hosts_cache.probationary_deletedNumber of probationary hosts* deleted in the hosts cache. *Probationary hosts are hosts that have never been the source of packets and bytes. These hosts are deleted first when clearing up space in the host cache.Cumulative
interfaces.fpsOutbound number of interface statistics per second exported to Vertica.Interval
security_events_cache.activeNumber of active security events in the security events cache.Snapshot
security_events_cache.droppedNumber of security events dropped because the security events cache is full.Cumulative
security_events_cache.endedNumber of ended security events in the security events cache.Cumulative
security_events_cache.insertedNumber of security events inserted into the database table.Interval
security_events_cache.maxMaximum size of the security events cache.Interval
Metric Identification Description Collection Type
security_events_cache.percentagePercent of capacity of the security events cache.Interval
security_events_cache.startedNumber of started security events in the security events cache.Cumulative
session_cache.activeNumber of active sessions from ISE in the session cache.Snapshot
session_cache.deletedNumber of deleted sessions from ISE in the session cache.Cumulative
session_cache.droppedNumber of sessions from ISE dropped because the sessions cache is full.Cumulative
session_cache.newNumber of new sessions from ISE added into the session cache.Cumulative
users_cache.activeNumber of active users in the users cache.Snapshot
users_cache.deletedNumber of deleted users in the users cache because they have timed out.Cumulative
users_cache.droppedNumber of users dropped because the users cache is full.Cumulative
users_cache.newNumber of new users in the users cache.Cumulative
reset_hourFlow Collector reset hour.N/A
vertica_stats.query_duration_sec_maxMaximum query response time.Cumulative
vertica_stats.query_duration_sec_minMinimum query response time.Cumulative
vertica_stats.query_duration_sec_avgAverage query response time.Cumulative

Flow Collector StatsD

Metric Identification Description Collection Type
exporters.fc_countNumber of exporters per Flow Collector.Interval
ndr-agent.unprocessable_findingNumber of NDR findings deemed unprocessable.Cumulative cleared daily
ndr-agent.ownership_registration_failedTechnical detail: Number of certain kind of errors that happened during NDR finding processing.Cumulative cleared daily
ndr-agent.upload_successNumber of NDR findings successfully processed by the agent.Cumulative cleared daily
ndr-agent.upload_failureNumber of NDR findings unsuccessfully uploaded by the agent.Cumulative cleared daily
ndr-agent.processing_failureNumber of failures observed during NDR processing.Cumulative cleared daily
ndr-agent.processing_successNumber of successfully processed NDR findings.Cumulative cleared daily
ndr-agent.old_file_deleteNumber of files deleted due to being too old.Cumulative cleared daily
ndr-agent.old_registration_deleteNumber of ownership registrations revoked due to being too old.Cumulative cleared daily
Metric Identification Description Collection Type
netflowTotal NetFlow records from all Netflow exporters. Includes NVM records.Cumulative cleared daily
fs_netflowNetflow records received from Flow Sensors only.Cumulative cleared daily
netflow_bytesTotal NetFlow bytes received from any NetFlow exporter. Includes NVM records.Cumulative cleared daily
fs_netflow_bytesNetFlow bytes received from Flow Sensors only.Cumulative cleared daily
sflowsFlow records received from any sFlow exporter.Cumulative cleared daily
sflow_bytessFlow bytes received from any sFlow exporter.Cumulative cleared daily
nvm_endpointUnique NVM endpoints seen today (before daily reset).Cumulative cleared daily
nvm_bytesNVM bytes received (including flow, endpoint, and endpoint_interface records).Cumulative cleared daily
nvm_netflowNVM bytes received (including flow, endpoint, and endpoint_interface records).Cumulative cleared daily
all_sal_eventAll Security Analytics and Logging (OnPrem) events received (including Adaptive Security Appliance and non-Adaptive Security Appliance), counted by number of events received.Cumulative cleared daily
all_sal_bytesAll Security Analytics and Logging (OnPrem)Cumulative cleared daily
Metric Identification Description Collection Type
ftd_sal_eventSecurity Analytics and Logging (OnPrem) (non-Adaptive Security Appliance) events received from Firepower Threat Defense/NGIPS devices only.Cumulative cleared daily
ftd_sal_bytesSecurity Analytics and Logging (OnPrem) (non-Adaptive Security Appliance) bytes received from Firepower Threat Defense/NGIPS devices only.Cumulative cleared daily
ftd_lina_bytesData Plane bytes received from Firepower Threat Defense devices only.Cumulative cleared daily
ftd_lina_eventData Plane events received from Firepower Threat Defense devices only.Cumulative cleared daily
asa_asa_eventAdaptive Security Appliance events received from Adaptive Security Appliance devices only.Cumulative cleared daily
asa_asa_bytesASA bytes received from Adaptive Security Appliance devices only.Cumulative cleared daily

Manager

Metric Identification Description Collection Type
exporter_cleaner_cleaning_enabledIndicates whether the Inactive Interfaces and Exporters Cleaner is enabled.Snapshot
exporter_cleaner_inactive_thresholdNumber of hours an exporter can be inactive before it is removed.Snapshot
exporter_cleaner_using_legacy_cleanerIndicates whether the Cleaner should use the legacy cleaning functionality.Snapshot
exporter_cleaner_hours_after_resetNumber of hours after reset that a domain should be cleaned.Snapshot
exporter_cleaner_interface_without_status_presumed_staleIndicates whether the Cleaner removes interfaces that were unknown to a Flow Collector at the last reset hour, treating them as inactive.Snapshot
ndrcoordinator.files_uploadedIndicates whether Secure Network Analytics deployment works as Data Store.Snapshot
report_completeName of the report and the run-time in milliseconds (Manager only).N/A
report_params Filters used when the Manager queries the Flow Collector databases. Data exported per query:
  • maximum number of rows
  • include-interface-data flag
  • fast-query flag
  • exclude-counts flag
  • flows direction filters
  • order-by column
  • default-columns flag
  • Time window start date and time
  • Time window end date and time
  • Number of device ids criteria
  • Number of interface ids criteria
Snapshot Frequency: Per Request
domain.integration_ad_countNumber of AD connections.Cumulative
domain.rpe_countNumber of role policies configured.Cumulative
domain.hg_changes_countChanges to the Host Group configuration.Cumulative

Manager StatsD

Metric Identification Description Collection Type
ndrcoordinator.analytics_enabledMarks whether Analytics is enabled. 1 if yes, 0 if no.Snapshot
ndrcoordinator.agents_contactedNumber of NDR agents contacted during the last contact.Snapshot
ndrcoordinator.processing_errorsNumber of errors during NDR finding processing.Cumulative
ndrcoordinator.files_uploadedNumber of NDR findings uploaded for processing.Cumulative
ndrevents.processing_errorsNumber of files failed to process because the system did not deliver the finding or could not parse the request.Cumulative
ndrevents.files_uploadedNumber of files that were sent to NDR events for processing.Cumulative
sna_swing_client_aliveInternal counter of API calls used by SNA Manager Desktop client.Snapshot
swrm_is_in_useResponse Management: Value is 1 if Response Management is used. Value is 0 if it is not used.Snapshot
swrm_rulesResponse Management: Number of custom rules.Snapshot
swrm_action_emailResponse Management: Number of custom actions of Email type.Snapshot
swrm_action_syslog_messageResponse Management: Number of custom actions of Syslog Message type.Snapshot
swrm_action_snmp_trapResponse Management: Number of custom actions of SNMP Trap type.Snapshot
swrm_action_ise_ancResponse management: Number of custom actions of ISE ANC Policy type.Snapshot
swrm_action_webhookResponse Management: Number of custom actions of Webhook type.Snapshot
swrm_action_ctrResponse Management: Number of custom actions of threat response Incident type.Snapshot
Metric Identification Description Collection Type
va_ctVisibility Assessment: Calculated run-time in milliseconds.Snapshot
va_ceVisibility Assessment: Number of errors (when calculation crashes).Snapshot
va_hcsVisibility Assessment: Host count API response size in bytes (detect excessive response size).Snapshot
va_ssVisibility Assessment: Scanners API response size in bytes (detect excessive response size).Snapshot
va_sesVisibility Assessment: Security Events API response size in bytes (detect excessive response size).Snapshot
sal_input_sizeNumber of entries in the pipeline input queue.Snapshot Frequency: 1 minute
sal_completed_sizeNumber of entries in the completed batch queue.Snapshot Frequency: 1 minute
sal_flush_timeAmount of time in milliseconds since the last pipeline flush. Available with Security Analytics and Logging (OnPrem) Single-node only.Snapshot Frequency: 1 minute
sal_batches_succeededNumber of batches successfully written to the file. Available with Security Analytics and Logging (OnPrem) Single-node only.Interval Frequency: 1 minute
sal_batches_processedNumber of batches that were processed. Available with Security Analytics and Logging (OnPrem) Single-node only.Interval Frequency: 1 minute
sal_batches_failedNumber of batches that have failed to complete writing to the file. Available with Security Analytics and Logging (OnPrem) Single-node only.Interval Frequency: 1 minute
sal_files_movedNumber of files moved to the ready directory. Available with Security Analytics and Logging (OnPrem) Single-node only.Interval Frequency: 1 minute
sal_files_failedNumber of files that have failed to be moved. Available with Security Analytics and Logging (OnPrem) Single-node only.Interval Frequency: 1 minute
sal_files_discardedNumber of files discarded due to error. Available with Security Analytics and Logging (OnPrem) Single-node only.Interval Frequency: 1 minute
sal_rows_writtenNumber of rows written to the referenced file. Available with Security Analytics and Logging (OnPrem) Single-node only.Interval Frequency: 1 minute
sal_rows_processedNumber of rows that were processed. Available with Security Analytics and Logging (OnPrem) Single-node only.Interval Frequency: 1 minute
sal_rows_failedNumber of rows that failed to be written. Available with Security Analytics and Logging (OnPrem) Single-node only.Interval Frequency: 1 minute
Metric Identification Description Collection Type
sal_total_batches_succeededTotal number of batches successfully written to the file. Available with Security Analytics and Logging (OnPrem) Single-node only.App Start Frequency: 1 minute
sal_total_batches_processedTotal number of batches that were processed. Available with Security Analytics and Logging (OnPrem) Single-node only.App Start Frequency: 1 minute
sal_total_batches_failedTotal number of files that have failed to complete writing to the file. Available with Security Analytics and Logging (OnPrem) Single-node only.App Start Frequency: 1 minute
sal_total_files_movedTotal number of files moved to the ready directory. Available with Security Analytics and Logging (OnPrem) Single-node only.App Start Frequency: 1 minute
sal_total_files_failedTotal number of files that have failed to be moved. Available with Security Analytics and Logging (OnPrem) Single-node only.App Start Frequency: 1 minute
sal_total_files_discardedTotal number of files discarded due to error. Available with Security Analytics and Logging (OnPrem) Single-node only.App Start Frequency: 1 minute
sal_total_rows_writtenTotal number of rows written to the referenced file. Available with Security Analytics and Logging (OnPrem) Single-node only.App Start Frequency: 1 minute
sal_total_rows_processedTotal number of rows that were processed. Available with Security Analytics and Logging (OnPrem) Single-node only.App Start Frequency: 1 minute
sal_total_rows_failedTotal number of rows that failed to be written. Available with Security Analytics and Logging (OnPrem) Single-node only.App Start Frequency: 1 minute
sal_transformer_<transformer id>Number of transformation errors in this transformer. Available with Security Analytics and Logging (OnPrem) Single-node only.Interval Frequency: 1 minute
sal_bytes_per_eventAverage number of bytes per event received.Interval Frequency: 1 minute
sal_bytes_receivedNumber of bytes received from the UDP server.Interval Frequency: 1 minute
sal_events_receivedNumber of events received from the UDP server.Interval Frequency: 1 minute
sal_total_events_receivedTotal number of events received by the router.App Start
sal_events_droppedNumber of unparsable events dropped.Interval Frequency: 1 minute
sal_total_events_droppedTotal number of unparsable events dropped.App Start Frequency: 1 minute
sal_events_ignoredNumber of ignored/unsupported events.Interval Frequency: 1 minute
sal_total_events_ignoredTotal number of ignored/unsupported events.App Start Frequency: 1 minute
sal_receive_queue_sizeNumber of events in the receive queue.Snapshot Frequency: 1 minute
sal_events_per_secondIngest rate (events per second).Interval Frequency: 1 minute
sal_bytes_per_secondIngest rate (bytes per second).Interval Frequency: 1 minute
sna_trustsec_report_runsNumber of daily TrustSec report requests.Cumulative

UDP Director

Metric Identification Description Collection Type
sources_countNumber of sources.Snapshot
rules_countNumber of rules.Snapshot
packets_unmatchedMaximum unmatched packets.Snapshot
packets_droppedDropped packets eth0.Snapshot

All Appliances

Metric Identification Description Collection Type
platformHardware platform (ex: Dell 13G, KVM Virtual Platform).N/A
serialSerial number of the appliance.N/A
versionSecure Network Analytics version number (ex: 7.1.0).N/A
version_buildBuild number (ex: 2018.07.16.2249-0).N/A
version_patchPatch number.N/A
csm_versionCustomer Success Metrics code version (ex: 1.0.24-SNAPSHOT).N/A
power_supply.statusManager and Flow Collector power supply statistics.Snapshot
productInstanceNameSmart Licensing product identifier.N/A

Contacting Support

If you need technical support, please do one of the following:

Change History

Document Version Published Date Description
1_0August 18, 2025Initial Version.

Copyright Information

Cisco and the Cisco logo are trademarks or registered trademarks of Cisco and/or its affiliates in the U.S. and other countries. To view a list of Cisco trademarks, go to this URL: https://www.cisco.com/go/trademarks. Third-party trademarks mentioned are the property of their respective owners. The use of the word partner does not imply a partnership relationship between Cisco and any other company. (1721R)

Models: v7.5.3, Secure Network Analytics, Secure Network Analytics, Network Analytics, Analytics

File Info : application/pdf, 26 Pages, 524.02KB

PDF preview unavailable. Download the PDF instead.

7 5 3 Customer Success Metrics Configuration Guide DV 1 0

References

madbuild

Related Documents

Preview Cisco Secure Network Analytics System Configuration Guide 7.5.3
A comprehensive guide for configuring Cisco Secure Network Analytics (formerly Stealthwatch) version 7.5.3. This document details the setup and management of various appliances, including Managers, Data Nodes, Flow Collectors, Flow Sensors, and UDP Directors, to establish a secure and visible network environment.
Preview Cisco Secure Network Analytics SSL/TLS Certificates Guide v7.5.3
A comprehensive guide for managing SSL/TLS certificates on Cisco Secure Network Analytics appliances version 7.5.3, covering installation, replacement, and troubleshooting for enhanced network security.
Preview Cisco Secure Network Analytics Virtual Edition Appliance Installation Guide 7.5.2
This guide provides detailed instructions for installing Cisco Secure Network Analytics Virtual Edition appliances, including Manager, Data Store, Flow Collector, Flow Sensor, and UDP Director. It covers system requirements, deployment considerations, and configuration steps for network administrators across VMware, KVM, and Nutanix AHV environments.
Preview Cisco Secure Network Analytics Virtual Edition Appliance Installation Guide 7.5.3
This guide provides detailed instructions for installing Cisco Secure Network Analytics Virtual Edition appliances, including the Manager, Data Store, Flow Collector, Flow Sensor, and UDP Director. It covers system requirements, installation methods for VMware, KVM, and Nutanix AHV, and configuration steps for optimal network traffic analysis and security.
Preview Cisco Secure Network Analytics Virtual Edition Appliance Installation Guide 7.5.3
Comprehensive guide for installing Cisco Secure Network Analytics Virtual Edition appliances, covering Manager, Data Store, Flow Collector, Flow Sensor, and UDP Director components. Details deployment requirements, compatibility, resource allocation, and installation procedures for VMware, KVM, and Nutanix AHV environments.
Preview Cisco Secure Network Analytics Virtual Edition Appliance Installation Guide 7.5.2
Comprehensive installation guide for Cisco Secure Network Analytics Virtual Edition appliances (Manager, Data Store, Flow Collector, Flow Sensor, UDP Director) across VMware, KVM, and Nutanix AHV platforms. Covers prerequisites, deployment methods, and configuration steps.
Preview Cisco Secure Network Analytics Update Guide v7.5.3
Comprehensive guide for updating Cisco Secure Network Analytics (formerly Stealthwatch) appliances to version 7.5.3. Covers prerequisites, download procedures, backup, installation, and troubleshooting for network administrators.
Preview Cisco Secure Network Analytics Virtual Edition Appliance Installation Guide 7.4.2
This guide details the installation of Cisco Secure Network Analytics Virtual Edition appliances (Manager, Data Store, Flow Collector, Flow Sensor, UDP Director) version 7.4.2. It covers deployment on VMware and KVM, resource requirements, firewall configurations, and system setup.