We are happy to advise you!
1­-855­-778­-7246    Contact

Cisco Stealthwatch Security (SSO)


Course Overview

This course focuses on using Cisco Stealthwatch Enterprise from the perspective of a security analyst. The overarching goal of the course is to use Stealthwatch to investigate potential security issues and make initial determinations of whether to proceed with a more thorough investigation or to move on to the next potential threat.

Who should attend

This course is intended for individuals who are responsible for using Stealthwatch to monitor security policy, provide feedback on the configuration, and initiate incident response investigations. An entry-level security analyst is the ideal audience for this class.

  • Customers responsible for completing the initial configuration of the Stealthwatch System into their network.
  • Channel partners responsible for completing the initial configuration of the Stealthwatch System into a customer network.
  • Employees responsible for completing the initial configuration of the Stealthwatch System into a customer network


It is strongly recommended to complete the Stealthwatch Foundations training prior to taking this course.

Course Objectives

  • Describe how the Stealthwatch System provides network visibility through monitoring and detection.
  • Describe the goals of using Stealthwatch in the proactive and operational modes.
  • Define basic concepts of investigation and detection of potential security issues using the Stealthwatch System.
  • Complete workflows to identify indicators of compromise in your network.
  • Describe alarm types and alarm notification within Stealthwatch.
  • Explain the utility of maps in the Stealthwatch System.
  • Describe how the Stealthwatch System contributes to successful incident handling.

Outline: Cisco Stealthwatch Security (SSO)

Day One

  • Cisco Stealthwatch Security Course Overview
  • Introduction to Security
  • Using Stealthwatch in the Proactive Mode
  • Pattern Recognition
  • Investigation and Detection Using Stealthwatch
  • Lab: Using Top Reports and Flow Tables for Detection
  • Lab: Creating and Using Dashboards for Detection
  • Lab: Creating Custom Security Events
  • Lab: Proactive Investigation Practice

Day Two

  • Using Stealthwatch in the Operational Mode
  • Alarms and Alarm Response
  • Lab: Responding to Alarms
  • Maps
  • Lab: Using Maps for Incident Response
  • Host Identification
  • Lab: Identify Hosts Using Host Snapshot and Host Report
  • Culminating Scenario: Using Stealthwatch for Insider Threats
  • Security Best Practices in Stealthwatch
  • Cisco Stealthwatch Security Course Outcomes
Classroom Training

Duration 2 days

  • Canada: CAD 3,975
  • Cisco Learning Credits: 30 CLC
Click on town name or "Online Training" to book Schedule
This is an Instructor-Led Classroom course
Instructor-led Online Training:   This computer icon in the schedule indicates that this date/time will be conducted as Instructor-Led Online Training.
  *   This class is delivered by a partner.
United States

Currently there are no training dates scheduled for this course.  For enquiries please write to info@fastlaneca.com.