Enable event data sharing with Talos

Share malicious event data from your device with Talos, Cisco's threat intelligence organization. Sharing event data allows Talos to improve threat detection and response capabilities, provide more targeted security updates for your network, and deliver better protection against emerging threats.

For more information about Talos, see the Cisco Talos product page.

Note

The Enable event data sharing with Talos setting in Security Cloud Control and the Talos Threat Hunting Telemetry option in Cloud-Delivered Firewall Management Center are separate settings. The setting in Security Cloud Control shares malicious event data from your devices with Talos.

To add threat-hunting rules to the global intrusion policy and send events from those rules to Talos, enable Talos Threat Hunting Telemetry in Cloud-Delivered Firewall Management Center at Administration > Configuration > Intrusion Policy Preferences.

Enabling the Enable event data sharing with Talos toggle button does not automatically activate the Talos Threat Hunting Telemetry feature in Cloud-Delivered Firewall Management Center. For the best results with this feature, also enable the Talos Threat Hunting Telemetry in Cloud-Delivered Firewall Management Center. For more information, see Set Intrusion Policy Preferences.

Sharing event data with Talos is enabled by default. To opt out, follow this procedure:

Procedure


Step 1

From the Security Cloud Control Home page, click Firewall.

Step 2

Choose Administration > General Settings.

Step 3

Turn off the Enable event data sharing with Talos toggle button to disable this setting.

Note

Sharing event data enables Talos to provide relevant security insights for your network. Disabling this setting might limit your ability to fully leverage Talos's capabilities and could affect your network's defense against evolving threats.