Activities
The Activities page displays activity data from your environment using the Industry Standard Open Cybersecurity Schema Framework (OCSF), version 1.4. For details, see Open Cybersecurity Schema Framework. The normalized data are analyzed by Cisco XDR to generate Cisco XDR detections; these detections are then analyzed by the detection engine and may be correlated into incidents. For more information on detections, see Detections.
Note: The activity data is from Cisco XDR native sources only and it does not include integrated third-party products.
The network activities table currently supports network activities from the following activity sources:
-
Cisco ONA - The network activities from Cisco ONA sensor are displayed if ONA is installed in your on-premises environment. The network traffic from Cisco ONA will remain available in the Event Viewer in Secure Cloud Analytics until the migration is complete on October 24th, 2026.
-
Cisco Telemetry Broker - The network activities from Cisco Telemetry Broker are displayed if the Cisco Telemetry Broker sensor is installed in your on-premises environment. The network traffic from Cisco Telemetry Broker will remain available in the Event Viewer in Secure Cloud Analytics until the migration is complete on October 24th, 2026.
-
Cisco Meraki - The network activities from Meraki are displayed if the Cisco Meraki integration is configured on the Integrations page. For details, see Cisco Meraki Integration.
-
Oracle VCN Flow Logs - The network activities from Oracle VCN flow logs are displayed if the Oracle Cloud Infrastructure integration is configured on the Integrations page. For details, see Oracle Cloud Infrastructure Integration.
-
Cisco NVM - The network activities from Cisco Secure Client Network Visibility Module (NVM) are displayed if the XDR Default Deployment is installed on your endpoints. For more information on NVM, see Network Visibility Module in Cisco XDR and for details on the XDR Default Deployment, see Deployments.
Note: The Network Visibility Module captures network conversations as bidirectional flows and the network activities table displays unidirectional flows only. As a result, the table may show the same conversation in two rows, one for each direction.
Choose Investigate > Activities in the navigation menu and apply filters in the Filters drawer to view network activities from your endpoints. For more information, see Filter Activities.
Note: Data is not displayed on the Activities page until you apply filters in the Filters drawer.
You can filter the display of activities based on start time, source, transport protocol, source hostname, source IP address, source port, destination hostname, destination IP address, destination port, community ID, actor process, or actor parent process.
The Activities page will only display data after you apply filters in the Filters drawer. The Filters drawer automatically opens when you open the Activities page. You can also click the
(Filters) icon above the list of network activities to open the Filters drawer. Click Apply filters to save your filter options. The activities list will display activities that match the filter criteria and the Applied Filters area is displayed across the top of the activities list. Click the
(Expand) icon to display all the filter selections with the filter category and the filter tags. To remove a selected filter category, click the
(Delete) icon or click the X in the filter tag to remove a specific selection within the filter category and the list will refresh.
Note: The query will timeout after 10 minutes. To return results more quickly, narrow the time range or apply additional filters.
You can narrow the display of activities based on a specific timeframe in the Start time drop-down list. A banner at the top of the Activities page displays the query timestamp, indicating that the results reflect the data available when the query ran. Activities ingested after that time are not included. The selected time filter is anchored to that query time as you paginate through the results. Search results expire one hour after the timestamp. When results expire, click Refresh in the expiration message to rerun the search with the current filters. The refreshed results may include newly ingested activities. If you navigate away from the Activities page, you must reapply the filters.
-
Last hour - Displays the activities observed within the last 1 hour that match the filter criteria.
-
Last 24 hours - Displays the activities observed within the last 24 hours that match the filter criteria.
-
Last 7 days - Displays the activities that started within the last 7 days that match the filter criteria.
-
Custom range - Uses the Start time to search for activities between the selected start and end date and time that match the filter criteria.
In the Source IP and Destination IP fields, you must enter the full and exact IP address (IPv4 or IPv6). To filter for multiple IPs, separate each address with a comma.
If applicable, you can choose a filter operator in the top right corner of a field to refine your search.
-
Equals - Displays results that exactly match any of the specified values.
-
Does NOT equal - Displays results that do not exactly match any of the specified values.
-
Contains - Displays results that contain any of the specified values. For example, entering acme matches server.acme.test.
|
Column Name |
Description |
|---|---|
|
Start time |
Date and time the current activity's observation period began according to the activity source. |
|
Activity type |
Type of activity captured by the activity source. For example, Network Activity. |
|
Activity source |
Name of the source product that recorded the activity. For example, Cisco NVM. |
|
Source IP |
The IP address of the host sending the communication, relative to your location (Internal or External). The country flag next to the IP address reflects the geographical location of the endpoint and it is displayed for external IP addresses only. Click the |
|
Source port |
Port number used by the activity source to initiate the communication. |
|
Destination IP |
The IP address of the host receiving the communication, relative to your location (Internal or External). The country flag next to the IP address reflects the geographical location of the endpoint and it is displayed for external IP addresses only. Click the |
|
Destination port |
Port number where the host received the communication. |
|
Protocol |
Identifier of the protocol used in the flow communication. |
|
Bytes out |
Total amount of data sent from the source to the destination during this activity, in bytes. If the activity is a segment of a longer conversation, the aggregate values are displayed as Cumulative bytes out in the activity details drawer. Note: The Network Visibility Module receives network activities as bidirectional flows and displays it in the network activities as separate unidirectional rows. As a result, traffic is always displayed as outbound and there is no Bytes in value. The data sent from destination to the source is displayed as outbound data in the Bytes out column. |
|
Community ID |
A standardized flow identifier for a network flow that is generated from details, such as IP addresses and ports, to ensure that the same network conversation is recognized consistently across supported network sources. For more information, see Community ID Flow Hashing. Note: This is an optional column that is only available in the Table Settings drawer. For details, see Customize Columns. |
|
Actor process |
The process that initiated the activity. Details may include name, process ID, executable path, and command line. Note: This is an optional column that is only available in the Table Settings drawer. For details, see Customize Columns. |
|
Actor parent process |
The immediate parent of the actor process. It is the process that launched the actor process and provides context about its place in the process hierarchy. Note: This is an optional column that is only available in the Table Settings drawer. For details, see Customize Columns. |
You can reorder the columns in the table and select the columns displayed to customize the table for the data you want to view.
To reorder the table columns, click and drag a column header to the desired position in the table.
Click the
(Settings) icon to open the Table Settings drawer and check the check boxes next to the columns you want displayed in the network activities table and click Apply. The
(Lock) icon indicates that the column is mandatory and it is always displayed in the network activities table. You can reorder the columns by clicking the (Grabber) icon and dragging it to the desired position in the list. If custom columns are displayed, click Reset to default to reset the table column settings to its default values.

