CISCO Stealthwatch Free Training - NSEL Configuration on FTD - Lesson 5


In this lesson, you will learn how to configure Network Secure Event Logging (NSEL) on Cisco Firepower Threat Defense and verify the exported flow data in Cisco Stealthwatch.

The lesson explains the role of the Firepower Management Center, Security Management Center, and Flow Collector, then demonstrates how NSEL traffic is generated and monitored.

Table of Contents

What Is NSEL?

On Cisco Firepower Threat Defense, NSEL can export these flow records to a Cisco Stealthwatch Flow Collector. Stealthwatch then processes the information and makes it available for traffic visibility, monitoring, and investigation.

Network Secure Event Logging (NSEL) is Cisco’s flow-logging mechanism for firewall traffic. It records connection events such as connection creation, connection deletion, and network address translation activity.

NSEL and Stealthwatch Architecture

In this design, Cisco Firepower Threat Defense monitors traffic passing through the firewall and exports NSEL records to the Stealthwatch Flow Collector.

The Flow Collector receives and processes the exported flow data. The Stealthwatch Management Console provides the interface used to view, analyze, and investigate the collected network activity.

  • FTD: Generates and exports NSEL flow records.
  • Flow Collector: Receives and processes the flow data.
  • Stealthwatch Management Console: Displays and analyzes the collected information.

NSEL Configuration on FTD

The configuration is completed through Cisco Firepower Management Center. The objective is to define the Stealthwatch Flow Collector as the destination for NSEL records and then apply the configuration to the FTD device.

  1. Log in to Cisco Firepower Management Center.
  2. Open the platform or device settings for the target FTD.
  3. Configure the Stealthwatch Flow Collector as the NSEL destination.
  4. Select the interfaces and traffic directions that should generate flow records.
  5. Save the configuration.
  6. Deploy the changes to the FTD device.

The video above demonstrates the configuration process and shows how the NSEL export is associated with the Stealthwatch infrastructure.

Verifying Flow Data in Stealthwatch

After deploying the configuration, generate traffic through the FTD and confirm that the Flow Collector is receiving NSEL records.

  1. Generate traffic through the monitored FTD interfaces.
  2. Open the Stealthwatch Management Console.
  3. Search for the source or destination IP address used in the test.
  4. Confirm that the related flow records appear in the Stealthwatch interface.
  5. Verify that the expected interfaces, traffic direction, and connection details are visible.

If no records appear, verify network connectivity between the FTD and Flow Collector, confirm the collector destination settings, and make sure the latest FMC deployment completed successfully.

Conclusion

NSEL allows Cisco Firepower Threat Defense to export detailed connection and NAT events to Cisco Stealthwatch. By sending these records to the Flow Collector and analyzing them through the Stealthwatch Management Console, administrators gain better visibility into traffic passing through the firewall.

After completing the configuration, always verify that the collector is receiving flow records and that the expected traffic appears correctly in Stealthwatch.

Related Articles

Ehsan Emad is a networking and cybersecurity expert with four CCIE certifications, a CCDE, CISSP, and extensive industry experience. He creates practical tutorials that turn complex networking technologies into clear, real-world solutions.