Home / Podcasts / Episode 7
Tech Lounge Podcast · Episode 7

Cisco Secure Analytics (Stealthwatch) Explained: NDR for Modern Enterprise Networks

Published Oct 26 · Ehsan Emad

Episode Summary

In this episode of the Tech Lounge series, we explored one of the most important network security solutions:
NDR – Network Detection & Response.
We reviewed the architecture of Cisco Secure Analytics (SNA) — formerly known as Stealthwatch — analyzed
common customer challenges, and explained how network traffic analytics can detect malicious behavior
even without signatures.
? Topics we covered:
• What is NDR and why is it critical today?
• SNA architecture and components (Flow Collector, Flow Sensor, UDP Director, etc.)
• The role of telemetry and NetFlow in security visibility
• A brief demo of the SNA environment

Key Takeaways

  • Understand the role of NDR in modern network security.
  • Review Cisco Secure Analytics, formerly Stealthwatch.
  • Understand key components such as Flow Collector, Flow Sensor and UDP Director.
  • Learn how NetFlow and telemetry support network visibility.
  • See how traffic analytics can detect suspicious behavior without relying only on signatures.

Chapters

  1. What NDR is
  2. Cisco Secure Analytics overview
  3. SNA architecture and components
  4. Telemetry and NetFlow
  5. Behavior-based detection
  6. Environment demo

Detailed Notes

The episode introduces NDR and then focuses on Cisco Secure Analytics architecture.
It explains how telemetry and flow data provide visibility into behavior across the network.

Speaker

Ehsan Emad