CISCO Stealthwatch Free Training - Host Groups - Module 3 - Lesson 9


In this lesson, you will learn how to organize Cisco Stealthwatch network visibility by creating Host Groups in the Stealthwatch Management Console.

Host Groups allow administrators to segment monitored systems into logical categories such as data centers, branches, departments, server networks, user networks, and security zones. The lesson also introduces the Classification App and explains how classification information supports host organization and analysis.

Table of Contents

What Are Stealthwatch Host Groups?

Host Groups are logical containers used to organize monitored IP addresses and networks inside Cisco Stealthwatch.

Instead of reviewing every host as an unrelated system, administrators can group hosts according to their location, business function, security role, ownership, or network segment.

Examples of Host Groups include:

  • Data Center Servers
  • Branch Offices
  • Finance Department
  • Human Resources
  • Management Systems
  • DMZ Servers
  • Employee Networks
  • Guest Networks
  • Critical Infrastructure

Why Use Host Groups?

Host Groups provide context for flow data. A flow record shows which systems communicated, but a Host Group helps explain what those systems represent in the organization.

Host Groups can make it easier to:

  • Separate internal networks by function or location
  • Identify traffic between security zones
  • Review activity for a specific department
  • Investigate communication involving critical systems
  • Compare traffic between server and user networks
  • Apply monitoring and analysis to defined network segments
  • Understand the business context of an IP address

For example, communication between two employee networks may be expected, while unexpected communication from a guest network to a critical server group may require investigation.

Planning the Segmentation Structure

Before creating Host Groups, define a clear segmentation model. The structure should reflect how the organization actually manages and secures its network.

Possible segmentation approaches include:

  • Location-based: Head office, branch office, data center, cloud, and remote sites
  • Department-based: Finance, Human Resources, Engineering, Sales, and Operations
  • Security-based: Trusted, untrusted, DMZ, guest, management, and restricted networks
  • Service-based: Web servers, database servers, DNS servers, authentication servers, and application servers
  • Criticality-based: Critical, production, development, test, and low-priority systems

A good Host Group structure should be easy to understand, maintain, and expand. Avoid creating groups with unclear names or overlapping IP ranges unless the design specifically requires them.

Configuring Host Groups

Host Groups are configured in the Stealthwatch Management Console. The exact menu names may vary by software version, but the general workflow remains similar.

  1. Log in to the Stealthwatch Management Console.
  2. Open the configuration area used to manage Host Groups.
  3. Create a new Host Group.
  4. Enter a clear and descriptive group name.
  5. Add the required IP addresses, subnets, or network ranges.
  6. Place the group under the appropriate parent group when using a hierarchy.
  7. Review the configured network ranges.
  8. Save the Host Group configuration.
  9. Confirm that the expected hosts appear in the new group.

Use descriptive names that explain the group’s purpose. A name such as Toronto-Data-Center-Servers is more useful than a generic name such as Group-1.

Example Host Group Structure

  • Corporate Network
    • Data Centers
    • Branch Offices
    • Employee Networks
    • Guest Networks
    • Management Networks

A hierarchical structure can make large environments easier to navigate and analyze.

Understanding the Classification App

The Classification App provides additional context about monitored hosts. Classification information can help administrators understand the role or behavior of systems observed through network telemetry.

This information can complement Host Groups. Host Groups describe where a system belongs in the organization, while classification can provide more information about what the system appears to be doing or which role it performs.

Together, Host Groups and classification information can improve:

  • Traffic analysis
  • Host identification
  • Security investigations
  • Policy planning
  • Network segmentation reviews

Video Demonstration

The following video demonstrates Host Group configuration in the Stealthwatch Management Console and introduces the Classification App.

Verifying Host Group Membership

After creating a Host Group, verify that the expected addresses and networks are associated with it.

  1. Open the Host Group configuration.
  2. Review the configured IP addresses and network ranges.
  3. Confirm that the subnet masks or prefix lengths are correct.
  4. Search for a known host from the configured network.
  5. Verify that the host appears under the expected Host Group.
  6. Review recent flows involving that host.
  7. Confirm that reports and investigations display the correct group context.

Testing with a known IP address is an effective way to detect incorrect prefixes, missing ranges, or unintended overlap.

Host Group Best Practices

  • Use clear and consistent naming conventions.
  • Organize groups according to business and security requirements.
  • Use hierarchical groups for large environments.
  • Avoid unnecessary overlap between network ranges.
  • Document the owner and purpose of important groups.
  • Review Host Groups when network addressing changes.
  • Remove obsolete networks and unused groups.
  • Validate critical groups with known test addresses.
  • Keep production, management, guest, and DMZ networks clearly separated.

Basic Troubleshooting

A Host Appears in the Wrong Group

  • Check for overlapping IP ranges.
  • Verify the configured subnet mask or prefix length.
  • Review the Host Group hierarchy.
  • Confirm that the host IP address has not changed.

A Host Does Not Appear in Any Expected Group

  • Confirm that the host address is included in the configured range.
  • Verify that Stealthwatch is receiving flow data for the host.
  • Check whether the correct network was added to the group.
  • Review the latest Host Group configuration.

Group Information Is Not Useful During Investigation

  • Rename unclear groups.
  • Separate broad groups into more meaningful subgroups.
  • Add business or security context to the segmentation design.
  • Review whether the current grouping reflects the real network architecture.

Conclusion

Host Groups provide organizational and security context for the flow data collected by Cisco Stealthwatch. They allow administrators to segment monitored networks by location, department, service, criticality, or security zone.

A well-designed Host Group hierarchy makes traffic analysis and security investigations easier because each IP address is associated with a meaningful part of the environment.

The Classification App can provide additional context about monitored systems and complement the segmentation created through Host Groups.

Related Reading