cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
964
Views
5
Helpful
0
Comments
Jason Kunst
Cisco Employee
Cisco Employee

 

Introduction

 

A solution the allows SecureX to act on data from Cisco Anyconnect NVM 

https://www.cisco.com/c/en/us/products/security/endpoint-security-analytics-built-on-splunk/index.html

 

Getting started with SecureX

SecureX requires at least one licensed Cisco product. Here is the page for it, with link for Free Trial.

 

The solution requires the following components:

  • Cisco Anyconnect NVM module
  • Splunk box running (see CESA POV for more information)
    • NVM collector (can run on a separate host)
    • NVM TA Add-on (process the data fields and normalize for consumption)
    • CESA NVM dashboard (optional) is not required but can be installed if the customer is going to use CESA on splunk)
    • SecureX relay does not support Splunk clustering
  • Cisco SecureX CESA Relay App on Splunk 

cisco-securex-relay-app-splunk.png

Setup

CESA Overview

https://www.cisco.com/c/en/us/support/docs/security/anyconnect-secure-mobility-client/200600-Install-and-Configure-Cisco-Network-Visi.html

For SecureX setup see the readme in the doc attached to the Splunk App

 

Demos

FAQ

Support

  • For CESA support please see http://cs.co/cesa-pov 
  • For SecureX support see support under the Splunk app

Display

Splunk_CESA_Sightings[1].png

 

 

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: