Activities

The Activities page displays activity data from your environment using the Industry Standard Open Cybersecurity Schema Framework (OCSF), version 1.4. For details, see Open Cybersecurity Schema Framework. The normalized data are analyzed by Cisco XDR to generate Cisco XDR detections; these detections are then analyzed by the detection engine and may be correlated into incidents. For more information on detections, see Detections.

Note: The activity data is from Cisco XDR native sources only and it does not include integrated third-party products.

The network activities table currently supports network activities from the following activity sources:

  • Cisco ONA - The network activities from Cisco ONA sensor are displayed if ONA is installed in your on-premises environment. The network traffic from Cisco ONA  will remain available in the Event Viewer in Secure Cloud Analytics until the migration is complete on October 24th, 2026.

  • Cisco Telemetry Broker - The network activities from Cisco Telemetry Broker are displayed if the Cisco Telemetry Broker sensor is installed in your on-premises environment. The network traffic from Cisco Telemetry Broker will remain available in the Event Viewer in Secure Cloud Analytics until the migration is complete on October 24th, 2026.

  • Cisco Meraki - The network activities from Meraki are displayed if the Cisco Meraki integration is configured on the Integrations page. For details, see Cisco Meraki Integration.

  • Oracle VCN Flow Logs - The network activities from Oracle VCN flow logs are displayed if the Oracle Cloud Infrastructure integration is configured on the Integrations page. For details, see Oracle Cloud Infrastructure Integration.

  • Cisco NVM - The network activities from Cisco Secure Client Network Visibility Module (NVM) are displayed if the XDR Default Deployment is installed on your endpoints. For more information on NVM, see Network Visibility Module in Cisco XDR and for details on the XDR Default Deployment, see Deployments.

    Note: The Network Visibility Module captures network conversations as bidirectional flows and the network activities table displays unidirectional flows only. As a result, the table may show the same conversation in two rows, one for each direction.

Choose InvestigateActivities in the navigation menu and apply filters in the Filters drawer to view network activities from your endpoints. For more information, see Filter Activities.

Note: Data is not displayed on the Activities page until you apply filters in the Filters drawer.