Güvenli Ağ Analizi
“
Ürün Bilgileri
Özellikler:
- Product Name: Cisco Secure Network Analytics
- Sürüm: 7.5.3
- Features: Customer Success Metrics
- Requirements: Internet access, Cisco Security Service
Değişme
Ürün Kullanım Talimatları
Configuring the Network Firewall:
To allow communication from your Cisco Secure Network Analytics
appliances to the cloud:
- Ensure appliances have Internet access.
- Configure your network firewall on the Manager to allow
iletişim.
Configuring the Manager:
To configure your network firewall for Managers:
- Allow communication to the following IP addresses and port
443: - api-sse.cisco.com
- kuruluş.sco.cisco.com
- mx*.sse.itd.cisco.com
- dex.sse.itd.cisco.com
- eventing-ingest.sse.itd.cisco.com
- If public DNS is restricted, locally resolve the IPs on your
Managers.
Disabling Customer Success Metrics:
To disable Customer Success Metrics on an appliance:
- Log in to your Manager.
- Select Configure > Global > Central Management.
- Click the (Ellipsis) icon for the appliance and choose Edit
Appliance Configuration. - In the General tab, scroll to External Services and uncheck
Enable Customer Success Metrics. - Click Apply Settings and save changes as prompted.
- Confirm Appliance Status returns to Connected on the Central
Management Inventory tab.
SSS (Sıkça Sorulan Sorular)
How do I know if Customer Success Metrics is enabled?
Customer Success Metrics is automatically enabled on your Secure
Network Analytics appliances.
What data is generated by Secure Network Analytics?
Secure Network Analytics generates a JSON file with metrics data
which is sent to the cloud.
"`
Cisco Güvenli Ağ Analitiği
Customer Success Metrics Configuration Guide 7.5.3
İçindekiler
Üzerindeview
3
Configuring the Network Firewall
4
Yöneticiyi Yapılandırma
4
Disabling Customer Success Metrics
5
Customer Success Metrics Data
6
Collection Types
6
Metrics Details
6
Akış Toplayıcı
7
Flow Collector StatsD
10
Müdür
12
Manager StatsD
16
UDP Direktörü
22
All Appliances
23
Destek ile İletişime Geçme
24
Değişiklik Geçmişi
25
© 2025 Cisco Systems, Inc. ve/veya bağlı kuruluşları. Her hakkı saklıdır.
-2-
Üzerindeview
Üzerindeview
Customer Success Metrics enables Cisco Secure Network Analytics (formerly Stealthwatch) data to be sent to the cloud so that we can access vital information regarding the deployment, health, performance, and usage of your system.
l Enabled: Customer Success Metrics is automatically enabled on your Secure Network Analytics appliances.
l Internet Access: Internet access is required for Customer Success Metrics. l Cisco Security Service Exchange: Cisco Security Service Exchange is enabled
automatically in v7.5.x and is required for Customer Success Metrics. l Data Files: Secure Network Analytics generates a JSON file with the metrics data.
The data is deleted from the appliance immediately after it is sent to the cloud.
Bu kılavuz aşağıdaki bilgileri içerir:
l Configuring the Firewall: Configure your network firewall to allow communication from your appliances to the cloud. Refer to Configuring the Network Firewall.
l Disabling Customer Success Metrics: To opt out of Customer Success Metrics, refer to Disabling Customer Success Metrics.
l Customer Success Metrics: For details about the metrics, refer to Customer Success Metrics Data.
For information on data retention and how to request deletion of usage metrics collected by Cisco, refer to Cisco Secure Network Analytics Privacy Data Sheet. For assistance, please contact Cisco Support.
© 2025 Cisco Systems, Inc. ve/veya bağlı kuruluşları. Her hakkı saklıdır.
-3-
Configuring the Network Firewall
Configuring the Network Firewall
To allow communication from your appliances to the cloud, configure your network firewall on your Cisco Secure Network Analytics Manager (formerly Stealthwatch Management Console).
Make sure your appliances have Internet access.
Yöneticiyi Yapılandırma
Configure your network firewall to allow communication from your Managers to the following IP addresses and port 443:
l api-sse.cisco.com l est.sco.cisco.com l mx*.sse.itd.cisco.com l dex.sse.itd.cisco.com l eventing-ingest.sse.itd.cisco.com
If public DNS is not allowed, make sure you configure the resolution locally on your Managers.
© 2025 Cisco Systems, Inc. ve/veya bağlı kuruluşları. Her hakkı saklıdır.
-4-
Disabling Customer Success Metrics
Disabling Customer Success Metrics
Use the following instructions to disable Customer Success Metrics on an appliance.
1. Log in to your Manager. 2. Select Configure > Global> Central Management. 3. Click the (Ellipsis) icon for the appliance. Choose Edit Appliance
Configuration. 4. Click the General tab. 5. Scroll to the External Services section. 6. Uncheck the Enable Customer Success Metrics check box. 7. Click Apply Settings. 8. Follow the on-screen prompts to save your changes. 9. On the Central Management Inventory tab, confirm the Appliance Status returns to
Connected. 10. To disable Customer Success Metrics on another appliance, repeat steps 3 through
9.
© 2025 Cisco Systems, Inc. ve/veya bağlı kuruluşları. Her hakkı saklıdır.
-5-
Customer Success Metrics Data
Customer Success Metrics Data
When Customer Success Metrics is enabled, the metrics are collected in the system and uploaded every 24 hours to the cloud. The data is deleted from the appliance immediately after it is sent to the cloud. We do not collect identification data such as host groups, IP addresses, user names, or passwords.
For information on data retention and how to request deletion of usage metrics collected by Cisco, refer to Cisco Secure Network Analytics Privacy Data Sheet.
Collection Types
Each metric is collected as one of the following collection types:
l App Start: One entry every 1 minute (collects all the data since the application started).
l Cumulative: One entry for a 24-hour period l Interval: One entry every 5 minutes (total of 288 entries per 24-hour period) l Snapshot: One entry for the point in time the report is generated
Some of the collection types are collected at different frequencies than the defaults we’ve described here, or they may be configured (depending on the application). Refer to Metrics Details for more information.
Metrics Details
We’ve listed the collected data by appliance type. Use Ctrl + F to search the tables by keyword.
© 2025 Cisco Systems, Inc. ve/veya bağlı kuruluşları. Her hakkı saklıdır.
-6-
Customer Success Metrics Data
Akış Toplayıcı
Metric Identification Description
devices_cache.active
Number of active MAC addresses from ISE in the devices cache.
Koleksiyon Türü
Anlık görüntü
devices_ cache.deleted
devices_ cache.dropped
devices_cache.new
flow_stats.fps flow_stats.flows
flow_cache.active
flow_cache.dropped
flow_cache.ended
flow_cache.max flow_ cache.percentage
flow_cache.started
hosts_cache.cached
Number of deleted MAC addresses from ISE in the devices cache because they have timed out.
kümülatif
Number of dropped MAC addresses from ISE because the devices cache is full.
kümülatif
Number of new MAC addresses from ISE added into the devices cache.
kümülatif
Outbound flows per second in the last minute. Interval
Inbound flows processed.
Aralık
Number of active flows in the Flow Collector flow cache.
Anlık görüntü
Number of flows dropped because the Flow Collector flow cache is full.
kümülatif
Number of flows ended in the Flow Collector flow cache.
Aralık
Maximum size of the Flow Collector flow cache. Interval
Percent of capacity of the Flow Collector flow cache
Aralık
Number of flows added to the Flow Collector flow cache.
kümülatif
Number of hosts in the host cache.
Aralık
© 2025 Cisco Systems, Inc. ve/veya bağlı kuruluşları. Her hakkı saklıdır.
-7-
Customer Success Metrics Data
Metric Identification Description
Koleksiyon Türü
hosts_cache.deleted Number of hosts deleted in the host cache.
kümülatif
hosts_cache.dropped
Number of hosts dropped because the host cache is full.
kümülatif
hosts_cache.max
Maximum size of the host cache.
Aralık
hosts_cache.new
Number of new hosts added into the host cache.
kümülatif
hosts_ cache.percentage
Percent of capacity of the host cache.
Aralık
hosts_ cache.probationary_ deleted
Number of probationary hosts* deleted in the hosts cache.
*Probationary hosts are hosts that have never been the source of packets and bytes. These hosts are deleted first when clearing up space in the host cache.
kümülatif
interfaces.fps
Outbound number of interface statistics per second exported to Vertica.
Aralık
security_events_ cache.active
Number of active security events in the security events cache.
Anlık görüntü
security_events_ cache.dropped
Number of security events dropped because the security events cache is full.
kümülatif
security_events_ cache.ended
Number of ended security events in the security events cache.
kümülatif
security_events_ cache.inserted
Number of security events inserted into the database table.
Aralık
security_events_ cache.max
Maximum size of the security events cache.
Aralık
© 2025 Cisco Systems, Inc. ve/veya bağlı kuruluşları. Her hakkı saklıdır.
-8-
Customer Success Metrics Data
Metric Identification Description
Koleksiyon Türü
security_events_ cache.percentage
Percent of capacity of the security events cache.
Aralık
security_events_ cache.started
Number of started security events in the security events cache.
kümülatif
session_cache.active
Number of active sessions from ISE in the session cache.
Anlık görüntü
session_ cache.deleted
Number of deleted sessions from ISE in the session cache.
kümülatif
session_ cache.dropped
Number of sessions from ISE dropped because the sessions cache is full.
kümülatif
session_cache.new
Number of new sessions from ISE added into the session cache.
kümülatif
users_cache.active
Number of active users in the users cache.
Anlık görüntü
users_cache.deleted
Number of deleted users in the users cache because they have timed out.
kümülatif
users_cache.dropped
Number of users dropped because the users cache is full.
kümülatif
users_cache.new
Number of new users in the users cache.
kümülatif
reset_hour
Flow Collector reset hour.
Yok
vertica_stats.query_ duration_sec_max
Maximum query response time.
kümülatif
vertica_stats.query_ duration_sec_min
Minimum query response time.
kümülatif
vertica_stats.query_ duration_sec_avg
Average query response time.
kümülatif
© 2025 Cisco Systems, Inc. ve/veya bağlı kuruluşları. Her hakkı saklıdır.
-9-
Customer Success Metrics Data
Metric Identification Description
exporters.fc_count
Number of exporters per Flow Collector.
Koleksiyon Türü
Aralık
Flow Collector StatsD
Metric Identification Description
ndragent.unprocessable_ finding
Number of NDR findings deemed unprocessable.
ndr-agent.ownership_ registration_failed
Technical detail: Number of certain kind of errors that happened during NDR finding processing.
ndr-agent.upload_ success
Number of NDR findings successfully processed by the agent.
ndr-agent.upload_ failure
Number of NDR findings unsuccessfully uploaded by the agent.
ndr-agent.processing_ Number of failures observed during NDR
arıza
işleme.
ndr-agent.processing_ Number of successfully processed NDR
başarı
findings.
ndr-agent.old_file_ delete
Sayısı files deleted due to being too old.
ndr-agent.old_ registration_delete
Number of ownership registrations revoked due to being too old.
Koleksiyon Türü
Cumulative cleared daily
Cumulative cleared daily
Cumulative cleared daily
Cumulative cleared daily
Cumulative cleared daily
Cumulative cleared daily
Cumulative cleared daily
Cumulative cleared daily
© 2025 Cisco Systems, Inc. ve/veya bağlı kuruluşları. Her hakkı saklıdır.
– 10 –
Customer Success Metrics Data
Metric Identification netflow fs_netflow netflow_bytes fs_netflow_bytes sflow sflow_bytes nvm_endpoint nvm_bytes nvm_netflow
all_sal_event all_sal_bytes
Tanım
Koleksiyon Türü
Total NetFlow records from all Netflow exporters. Includes NVM records.
Cumulative cleared daily
Netflow records received from Flow Sensors only.
Cumulative cleared daily
Total NetFlow bytes received from any NetFlow exporter. Includes NVM records.
Cumulative cleared daily
NetFlow bytes received from Flow Sensors only.
Cumulative cleared daily
sFlow records received from any sFlow exporter.
Cumulative cleared daily
sFlow bytes received from any sFlow exporter.
Cumulative cleared daily
Unique NVM endpoints seen today (before daily reset).
Cumulative cleared daily
NVM bytes received (including flow, endpoint, Cumulative
and endpoint_interface records).
cleared daily
NVM bytes received (including flow, endpoint, Cumulative
and endpoint_interface records).
cleared daily
All Security Analytics and Logging (OnPrem) events received (including Adaptive Security Appliance and non-Adaptive Security Appliance), counted by number of events received.
Cumulative cleared daily
All Security Analytics and Logging (OnPrem) Cumulative
© 2025 Cisco Systems, Inc. ve/veya bağlı kuruluşları. Her hakkı saklıdır.
– 11 –
Customer Success Metrics Data
Metric Identification
ftd_sal_event ftd_sal_bytes ftd_lina_bytes ftd_lina_event asa_asa_event asa_asa_bytes
Müdür
Tanım
Koleksiyon Türü
events received (including Adaptive Security Appliance and non-Adaptive Security Appliance, counted by number of bytes received.
cleared daily
Security Analytics and Logging (OnPrem) (non-Adaptive Security Appliance) events received from Firepower Threat Defense/NGIPS devices only.
Cumulative cleared daily
Security Analytics and Logging (OnPrem) (non-Adaptive Security Appliance) bytes received from Firepower Threat Defense/NGIPS devices only.
Cumulative cleared daily
Data Plane bytes received from Firepower Threat Defense devices only.
Cumulative cleared daily
Data Plane events received from Firepower Threat Defense devices only.
Cumulative cleared daily
Adaptive Security Appliance events received from Adaptive Security Appliance devices only.
Cumulative cleared daily
ASA bytes received from Adaptive Security Appliance devices only.
Cumulative cleared daily
Metric Identification Description
exporter_cleaner_ cleaning_enabled
Indicates whether the Inactive Interfaces and Exporters Cleaner is enabled.
Koleksiyon Türü
Anlık görüntü
© 2025 Cisco Systems, Inc. ve/veya bağlı kuruluşları. Her hakkı saklıdır.
– 12 –
Customer Success Metrics Data
Metric Identification Description
Koleksiyon Türü
exporter_cleaner_ inactive_threshold
Number of hours an exporter can be inactive before it is removed.
Anlık görüntü
exporter_cleaner_
Indicates whether the Cleaner should use the
using_legacy_cleaner legacy cleaning functionality.
Anlık görüntü
exporter_cleaner_ hours_after_reset
Number of hours after reset that a domain should be cleaned.
Anlık görüntü
exporter_cleaner_ interface_without_ status_presumed_ stale
Indicates whether the Cleaner removes interfaces that were unknown to a Flow Collector at the last reset hour, treating them as inactive.
Anlık görüntü
ndrcoordinator.files_ uploaded
Indicates whether Secure Network Analytics deployment works as Data Store.
Anlık görüntü
report_complete
Name of the report and the run-time in milliseconds (Manager only).
Yok
report_params
Filters used when the Manager queries the Flow Collector databases.
Data exported per query:
l maximum number of rows l include-interface-data flag l fast-query flag l exclude-counts flag l flows direction filters l order-by column l default-columns flag l Time window start date and time l Time window end date and time l Number of device ids criteria l Number of interface ids criteria
Anlık görüntü
Frequency: Per Request
© 2025 Cisco Systems, Inc. ve/veya bağlı kuruluşları. Her hakkı saklıdır.
– 13 –
Customer Success Metrics Data
Metric Identification Description
Koleksiyon Türü
l Number of IPs criteria
l Number of IP ranges criteria
l Number of hostgroups criteria
l Number of hosts pairs criteria
l Whether results are filtered by MAC addresses
l Whether results are filtered by TCP/UDP ports
l Number of user names criteria
l Whether results are filtered by number of bytes/packets
l Whether results are filtered by total number of bytes/packets
l Whether results are filtered by URL
l Whether results are filtered by protocols
l Whether results are filtered by applications ids
l Whether results are filtered by process name
l Whether results are filtered by process hash
l Whether results are filtered by TLS version
l Number of ciphers in cipher suite criteria
domain.integration_ ad_count
Number of AD connections.
kümülatif
domain.rpe_count
Number of role policies configured.
kümülatif
domain.hg_changes_ count
Changes to the Host Group configuration.
kümülatif
© 2025 Cisco Systems, Inc. ve/veya bağlı kuruluşları. Her hakkı saklıdır.
– 14 –
Customer Success Metrics Data
Metric Identification Description
Koleksiyon Türü
integration_snmp
SNMP agent usage.
Yok
integration_cognitive
Global threat alerts (formerly Cognitive Intelligence) integration enabled.
Yok
domain.services
Number of services defined.
Anlık görüntü
applications_default_ count
Number of applications defined.
Anlık görüntü
smc_users_count
Number of users in the Web Uygulama.
Anlık görüntü
login_api_count
Number of API log ins.
kümülatif
login_ui_count
Sayısı Web App log ins.
kümülatif
report_concurrency Number of reports running concurrently.
kümülatif
apicall_ui_count
Number of Manager API calls using the Web Uygulama.
kümülatif
apicall_api_count
Number of Manager API calls using the API.
kümülatif
ctr.enabled
Cisco SecureX threat response(formerly Cisco Threat Response) integration enabled.
Yok
ctr.alarm_sender_ enabled
Secure Network Analytics alarms to SecureX threat response enabled.
Yok
ctr.alarm_sender_ minimal_severity
Minimal severity of alarms sent to SecureX threat response.
Yok
ctr.enrichment_ enabled
Enrichment request from SecureX threat response enabled.
Yok
ctr.enrichment_limit
Number of top Security Events to be returned to SecureX threat response.
kümülatif
© 2025 Cisco Systems, Inc. ve/veya bağlı kuruluşları. Her hakkı saklıdır.
– 15 –
Customer Success Metrics Data
Metric Identification Description
Koleksiyon Türü
ctr.enrichment_period
Time period for Security Events to be returned to SecureX threat response.
kümülatif
ctr.number_of_ enrichment_requests
Number of enrichment requests received from SecureX threat response.
kümülatif
ctr.number_of_refer_ Number of requests for Manager pivot link
istekler
received from SecureX threat response.
kümülatif
ctr.xdr_number_of_ alarms
Daily count of alarms sent to XDR.
kümülatif
ctr.xdr_number_of_ alerts
Daily count of alerts sent to XDR.
kümülatif
ctr.xdr_sender_ enabled
True/False if sending is enabled.
Anlık görüntü
failover_role
Manager primary or secondary failover role in the cluster.
Yok
domain.cse_count
Number of custom security events for a domain ID.
Anlık görüntü
Manager StatsD
Metric Identification
Tanım
Koleksiyon Türü
ndrcoordinator.analytics_ enabled
Marks whether Analytics is enabled. 1 if yes, 0 if no.
Anlık görüntü
ndrcoordinator.agents_ contacted
Number of NDR agents contacted during the last contact.
Anlık görüntü
ndrcoordinator.processing_ Number of errors during NDR finding
hatalar
işleme.
kümülatif
© 2025 Cisco Systems, Inc. ve/veya bağlı kuruluşları. Her hakkı saklıdır.
– 16 –
Customer Success Metrics Data
Metric Identification
Tanım
Koleksiyon Türü
ndrcoordinator.files_ uploaded
Number of NDR findings uploaded for processing.
kümülatif
ndrevents.processing_errors
Sayısı files failed to process because the system did not deliver the finding or could not parse the request.
kümülatif
ndrevents.files_uploaded
Sayısı files that were sent to NDR events for processing.
kümülatif
sna_swing_client_alive
Internal counter of API calls used by SNA Manager Desktop client.
Anlık görüntü
swrm_is_in_use
Response Management: Value is 1 if Response Management is used. Value is 0 if it is not used.
Anlık görüntü
swrm_rules
Response Management: Number of custom rules.
Anlık görüntü
swrm_action_email
Response Management: Number of custom actions of Email type.
Anlık görüntü
swrm_action_syslog_ message
Response Management: Number of custom actions of Syslog Message type.
Anlık görüntü
swrm_action_snmp_trap
Response Management: Number of custom actions of SNMP Trap type.
Anlık görüntü
swrm_action_ise_anc
Response Management: Number of custom actions of ISE ANC Policy type.
Anlık görüntü
swrm_action_webkanca
Response Management: Number of custom actions of Webhook type.
Anlık görüntü
swrm_action_ctr
Response Management: Number of custom actions of threat response Incident type.
Anlık görüntü
© 2025 Cisco Systems, Inc. ve/veya bağlı kuruluşları. Her hakkı saklıdır.
– 17 –
Customer Success Metrics Data
Metric Identification va_ct va_ce va_hcs va_ss va_ses sal_input_size sal_completed_size
sal_flush_time
sal_batches_succeeded
Tanım
Koleksiyon Türü
Visibility Assessment: Calculated runtime in milliseconds.
Anlık görüntü
Visibility Assessment: Number of errors (when calculation crashes).
Anlık görüntü
Visibility Assessment: Host count API response size in bytes (detect excessive response size).
Anlık görüntü
Visibility Assessment: Scanners API response size in bytes (detect excessive response size).
Anlık görüntü
Visibility Assessment: Security Events API response size in bytes (detect excessive response size).
Anlık görüntü
Number of entries in the pipeline input queue.
Anlık görüntü
Frequency: 1 minute
Number of entries in the completed batch queue.
Anlık görüntü
Frequency: 1 minute
Amount of time in milliseconds since the last pipeline flush.
Available with Security Analytics and Logging (OnPrem) Single-node only.
Anlık görüntü
Frequency: 1 minute
Number of batches successfully written to the file.
Available with Security Analytics and Logging (OnPrem) Single-node only.
Aralık
Frequency: 1 minute
© 2025 Cisco Systems, Inc. ve/veya bağlı kuruluşları. Her hakkı saklıdır.
– 18 –
Customer Success Metrics Data
Metric Identification sal_batches_processed sal_batches_failed sal_files_moved sal_files_failed sal_files_discarded sal_rows_written sal_rows_processed sal_rows_failed
Tanım
Koleksiyon Türü
Number of batches that were processed. Interval
Available with Security Analytics and Logging (OnPrem) Single-node only.
Frequency: 1 minute
Number of batches that have failed to complete writing to the file.
Available with Security Analytics and Logging (OnPrem) Single-node only.
Aralık
Frequency: 1 minute
Sayısı files moved to the ready directory.
Available with Security Analytics and Logging (OnPrem) Single-node only.
Aralık
Frequency: 1 minute
Sayısı files that have failed to be moved.
Available with Security Analytics and Logging (OnPrem) Single-node only.
Aralık
Frequency: 1 minute
Sayısı files discarded due to error.
Available with Security Analytics and Logging (OnPrem) Single-node only.
Aralık
Frequency: 1 minute
Number of rows written to the referenced file.
Available with Security Analytics and Logging (OnPrem) Single-node only.
Aralık
Frequency: 1 minute
Number of rows that were processed.
Available with Security Analytics and Logging (OnPrem) Single-node only.
Aralık
Frequency: 1 minute
Number of rows that failed to be written. Interval
Available with Security Analytics and
Sıklık:
© 2025 Cisco Systems, Inc. ve/veya bağlı kuruluşları. Her hakkı saklıdır.
– 19 –
Customer Success Metrics Data
Metric Identification
sal_total_batches_ succeeded sal_total_batches_ processed sal_total_batches_failed
sal_total_files_moved
sal_total_files_failed
sal_total_files_discarded sal_total_rows_written
Tanım
Koleksiyon Türü
Logging (OnPrem) Single-node only.
1 dakika
Total number of batches successfully written to the file.
Available with Security Analytics and Logging (OnPrem) Single-node only.
App Start
Frequency: 1 minute
Total number of batches that were processed.
Available with Security Analytics and Logging (OnPrem) Single-node only.
App Start
Frequency: 1 minute
Toplam sayısı files that have failed to complete writing to the file.
Available with Security Analytics and Logging (OnPrem) Single-node only.
App Start
Frequency: 1 minute
Toplam sayısı files moved to the ready directory.
Available with Security Analytics and Logging (OnPrem) Single-node only.
App Start
Frequency: 1 minute
Toplam sayısı files that have failed to be moved.
Available with Security Analytics and Logging (OnPrem) Single-node only.
App Start
Frequency: 1 minute
Toplam sayısı files discarded due to error.
Available with Security Analytics and Logging (OnPrem) Single-node only.
App Start
Frequency: 1 minute
Total number of rows written to the referenced file.
Available with Security Analytics and
App Start
Frequency: 1 minute
© 2025 Cisco Systems, Inc. ve/veya bağlı kuruluşları. Her hakkı saklıdır.
– 20 –
Customer Success Metrics Data
Metric Identification
sal_total_rows_processed
sal_total_rows_failed sal_transformer_ <transformer id> sal_bytes_per_event sal_bytes_received sal_events_received sal_total_events_received sal_events_dropped
Tanım
Koleksiyon Türü
Logging (OnPrem) Single-node only.
Total number of rows that were processed.
Available with Security Analytics and Logging (OnPrem) Single-node only.
App Start
Frequency: 1 minute
Total number of rows that failed to be written.
Available with Security Analytics and Logging (OnPrem) Single-node only.
App Start
Frequency: 1 minute
Number of transformation errors in this transformer.
Available with Security Analytics and Logging (OnPrem) Single-node only.
Aralık
Frequency: 1 minute
Average number of bytes per event received.
Aralık
Frequency: 1 minute
Number of bytes received from the UDP server.
Aralık
Frequency: 1 minute
Number of events received from the UDP server.
Aralık
Frequency: 1 minute
Total number of events received by the router.
App Start
Number of unparsable events dropped.
Aralık
Frequency: 1 minute
© 2025 Cisco Systems, Inc. ve/veya bağlı kuruluşları. Her hakkı saklıdır.
– 21 –
Customer Success Metrics Data
Metric Identification sal_total_events_dropped sal_events_ignored sal_total_events_ignored sal_receive_queue_size sal_events_per second sal_bytes_per_second sna_trustsec_report_runs
UDP Direktörü
Tanım
Koleksiyon Türü
Total number of unparsable events dropped.
App Start
Frequency: 1 minute
Number of ignored/unsupported events.
Aralık
Frequency: 1 minute
Total number of ignored/unsupported events.
App Start
Frequency: 1 minute
Number of events in the receive queue.
Anlık görüntü
Frequency: 1 minute
Ingest rate (events per second).
Aralık
Frequency: 1 minute
Ingest rate (bytes per second).
Aralık
Frequency: 1 minute
Number of daily TrustSec report requests.
kümülatif
Metric Identification Description
sources_count
Number of sources.
Koleksiyon Türü
Anlık görüntü
© 2025 Cisco Systems, Inc. ve/veya bağlı kuruluşları. Her hakkı saklıdır.
– 22 –
Customer Success Metrics Data
Metric Identification Description
rules_count packets_unmatched packets_dropped
Number of rules. Maximum unmatched packets. Dropped packets eth0.
Collection Type Snapshot Snapshot Snapshot
All Appliances
Metric Identification Description
Koleksiyon Türü
platform
Hardware platform (ex: Dell 13G, KVM Virtual Platform).
Yok
seri
Serial number of the appliance.
Yok
versiyon
Secure Network Analytics version number (ex: 7.1.0).
Yok
version_build
Build number (ex: 2018.07.16.2249-0).
Yok
version_patch
Patch number.
Yok
csm_version
Customer Success Metrics code version (ex: 1.0.24-SNAPSHOT).
Yok
power_supply.status
Manager and Flow Collector power supply statistics.
Anlık görüntü
productInstanceName Smart Licensing product identifier.
Yok
© 2025 Cisco Systems, Inc. ve/veya bağlı kuruluşları. Her hakkı saklıdır.
– 23 –
Destek ile İletişime Geçme
Destek ile İletişime Geçme
Teknik desteğe ihtiyacınız varsa lütfen aşağıdakilerden birini yapın: l Yerel Cisco İş Ortağınıza başvurun l Cisco Destek ile iletişime geçin l Bir vaka açmak için web: http://www.cisco.com/c/en/us/support/index.html l Telefon desteği için: 1-800-553-2447 (ABD) l Dünya çapında destek numaraları için: https://www.cisco.com/c/en/us/support/web/tsd-cisco-dünya çapında-contacts.html
© 2025 Cisco Systems, Inc. ve/veya bağlı kuruluşları. Her hakkı saklıdır.
– 24 –
Değişiklik Geçmişi
Belge Sürümü 1_0
Yayınlanma Tarihi 18 Ağustos 2025
Değişiklik Geçmişi
Description Initial Version.
© 2025 Cisco Systems, Inc. ve/veya bağlı kuruluşları. Her hakkı saklıdır.
– 25 –
Telif Hakkı Bilgileri
Cisco ve Cisco logosu, Cisco ve/veya bağlı şirketlerinin ABD ve diğer ülkelerdeki ticari markaları veya tescilli ticari markalarıdır. view Cisco ticari markalarının listesi için buraya gidin URL: https://www.cisco.com/go/trademarks. Adı geçen üçüncü taraf ticari markalar ilgili sahiplerinin mülkiyetindedir. Ortak kelimesinin kullanımı, Cisco ile başka herhangi bir şirket arasında bir ortaklık ilişkisi olduğu anlamına gelmez. (1721R)
© 2025 Cisco Systems, Inc. ve/veya bağlı kuruluşları. Her hakkı saklıdır.
Belgeler / Kaynaklar
![]() |
Cisco Güvenli Ağ Analitiği [pdf] Kullanıcı Kılavuzu v7.5.3, Secure Network Analytics, Secure Network Analytics, Network Analytics, Analytics |