Detection Findings

The Detection findings tab displays all the security events generated by integrated products and the Cisco XDR native telemetry sent from the following sources: Network, Cloud, Identity, and Endpoint. The security events allow you to validate the data that is ingested by Cisco XDR for incident correlation. For details on how the security events are grouped and enriched by the correlation engine in Cisco XDR to create incidents in Cisco XDR, see Detection. You can also create custom security events using the Findings Intake API. For more information, see Cisco Developer - Cisco XDR API Documentation.

The following is a list of supported Cisco and third-party products that generate security events if integrated in Cisco XDR:

The Cisco and third-party integrations are configured on the Integrations page. For details on adding an integration, see Integrations.

The Cisco XDR source refers to the Cisco XDR native telemetry sent from endpoint and the following sources that are integrated in Cisco Secure Cloud Analytics: network, cloud, and identity. For more information, see Cisco Secure Cloud Analytics. The Network Visibility Module data is sent to Cisco XDR from the endpoint source if you install the default deployment on your endpoints. For more information on installing the default deployment and viewing endpoints data, see Default Deployments.

You can filter the types of security events to narrow the list of results in the table.

Security detection findings table with filters for time, source, severity. Displays 305 results.

Choose InvestigateDetection Findings in the navigation menu to view the security events from Cisco XDR native sources and integrated products.