CISCO Stealthwatch Free Training - SMC GUI Interfaces - Lesson 7


In this lesson, you will learn how to navigate the main Cisco Stealthwatch interfaces and understand the purpose of each management interface.

The lesson covers the Appliance Administration Interface, the Stealthwatch Management Console web interface, and the desktop client interface available in version 7.0 and later.

Table of Contents

Stealthwatch Interface Overview

Cisco Stealthwatch provides different interfaces for system administration, traffic analysis, monitoring, investigation, and reporting.

The three interfaces discussed in this lesson are:

  1. Appliance Administration Interface
  2. Stealthwatch Management Console Web Interface
  3. Desktop Client Interface

Each interface serves a different operational purpose. Administrators should understand which interface to use for appliance configuration and which interface to use for flow analysis and security investigations.

Appliance Administration Interface

The Appliance Administration Interface is used for appliance-level configuration and system management.

Typical administrative tasks can include:

  • Configuring appliance network settings
  • Managing the appliance hostname
  • Configuring DNS and default-gateway information
  • Reviewing system status
  • Managing time and NTP settings
  • Reviewing appliance services
  • Performing maintenance operations
  • Managing software or appliance-related settings

This interface is primarily intended for administrators responsible for the health and base configuration of the Stealthwatch appliance.

When to Use the Appliance Administration Interface

  • During initial appliance deployment
  • When changing management network settings
  • When verifying appliance health
  • When managing system-level services
  • When troubleshooting appliance connectivity

SMC Web Interface

The Stealthwatch Management Console web interface provides centralized visibility into collected flow data and monitored network activity.

The SMC web interface can be used to:

  • Review dashboards
  • Monitor alarms and security events
  • Search for hosts and IP addresses
  • Analyze network conversations
  • Review traffic between Host Groups
  • Identify top talkers
  • Investigate unusual communication
  • Review bandwidth and protocol usage
  • Access reports and analytical views

The SMC web interface is the primary interface for day-to-day monitoring, traffic analysis, and security investigation.

Example Investigation Workflow

  1. Log in to the SMC web interface.
  2. Open the relevant dashboard or alarm view.
  3. Select the affected host or IP address.
  4. Review recent flow activity.
  5. Identify source and destination systems.
  6. Review ports, protocols, byte counts, and connection duration.
  7. Determine whether the activity is expected or requires further investigation.

Desktop Client Interface

The desktop client interface provides another way to interact with Stealthwatch data and operational views.

In environments where the desktop client is available, it can provide access to detailed monitoring, analysis, and investigation functions.

The desktop client may be used for:

  • Reviewing network activity
  • Analyzing flow records
  • Investigating hosts and conversations
  • Accessing operational views
  • Reviewing security and behavioral information

The available functions and interface layout can depend on the deployed Stealthwatch version. This lesson demonstrates the desktop client interface for version 7.0 and later.

Interface Comparison

Interface Primary Purpose Typical Users
Appliance Administration Interface Appliance configuration, health, and system administration System and platform administrators
SMC Web Interface Monitoring, flow analysis, alarms, reporting, and investigation Network and security operations teams
Desktop Client Interface Detailed operational analysis and investigation Network and security analysts

The Appliance Administration Interface manages the underlying appliance, while the SMC web interface and desktop client focus primarily on network visibility and analysis.

Use the following workflow when working with the Stealthwatch interfaces:

  1. Use the Appliance Administration Interface to verify appliance health and management connectivity.
  2. Open the SMC web interface for dashboards, alarms, host searches, and flow investigations.
  3. Use the desktop client when its detailed operational views are required.
  4. Confirm that user permissions provide access to the required functions.
  5. Use Host Groups and classification information to add context to investigations.
  6. Review flow records to understand communication between monitored systems.

Video Demonstration

The following video demonstrates the Appliance Administration Interface, SMC web interface, and desktop client interface.

Verifying Interface Access

After deployment or configuration changes, verify access to each required interface.

  1. Confirm that the appliance management IP address is reachable.
  2. Open the Appliance Administration Interface.
  3. Verify that administrative login succeeds.
  4. Open the SMC web interface.
  5. Confirm that dashboards and monitored data load correctly.
  6. Search for a known host or IP address.
  7. Verify that recent flow records are visible.
  8. Open the desktop client when it is part of the deployment.
  9. Confirm that the required views and functions are available.

Basic Troubleshooting

The Appliance Administration Interface Is Not Reachable

  • Verify the management IP address and subnet mask.
  • Confirm the default gateway.
  • Check DNS resolution when using a hostname.
  • Verify routing and firewall access between the administrator and appliance.
  • Confirm that the appliance is powered on and fully initialized.

The SMC Web Interface Opens but Data Is Missing

  • Confirm that Flow Collectors are connected.
  • Verify that exporters are sending flow records.
  • Review appliance and collector status.
  • Check the selected time range.
  • Confirm that the user has access to the relevant Host Groups.

A User Cannot Access a Required Menu

  • Review the user role and permissions.
  • Confirm that the account is assigned to the correct domain or data scope.
  • Verify that the feature exists in the deployed software version.
  • Sign out and sign in again after permission changes.

The Desktop Client Cannot Connect

  • Verify network connectivity to the SMC.
  • Confirm that the client and server versions are compatible.
  • Check the configured server address and port.
  • Review certificate or authentication errors.
  • Confirm that the required service is available.

Conclusion

Cisco Stealthwatch provides separate interfaces for appliance administration, centralized monitoring, and detailed analysis.

The Appliance Administration Interface is used for system-level configuration and appliance health. The SMC web interface provides dashboards, alarms, host searches, flow analysis, and reporting. The desktop client provides additional operational and investigative views where supported.

Understanding the role of each interface helps administrators select the correct tool for configuration, monitoring, and troubleshooting.

Related Reading