Cloud Data Exchange settings

Configure the connection between the ​eyeSight and the Forescout Cloudinstance with the following settings.

Cloud Settings

Address Cloud Uniform Resource Locator (URL) where the data will be uploaded.

Tip: The URLs will generate and display on the configuration screen when generating an API key.

Authorization Token Enter the API key obtained from the Forescout Cloud instance.

To obtain an API key, see Generate API Key (Forescout Cloud Administration Guide).

In the API Key Type, select Risk Sharing API.

Proxy Settings

If your Forescout device does not have a direct connection to the Internet, configure the Proxy Settings accordingly.

Use Proxy Use Proxy
  • Default Value: FALSE
Proxy Server IP/Name Proxy Server IP/Name  
Proxy Server Port Proxy Server Port
  • Default Value: 8080
  • Minimum Value: 1
  • Maximum Value: 65535
Use Proxy Credentials Use Proxy Credentials
  • Default Value: FALSE
Proxy Username Proxy Username  
Proxy Password Proxy Password  

Advanced General Settings

Focal Device Manages the communication between Forescout eyeSightand Forescout Cloud. It collects the data from all eyeSight devices and sends the data to Forescout Cloud from a central (focal) point.
  • Default Value: Enterprise Manager
Health Monitoring Upload Max Size (KB) Set the max size of the Health Monitoring upload (KB).

Maximum size of upload for health monitoring data. If amount of data is larger than the max size set, the upload will be split into multiple smaller uploads. Max size set by cloud is 5 mb.

  • Default Value: 4500
  • Minimum Value: 500
  • Maximum Value: 4500
Health Monitoring Upload Interval (minutes) Set the time interval (in minutes) in which health monitoring data is uploaded to cloud.

How often CDE uploads health monitoring data to cloud.

  • Default Value: 5
  • Minimum Value: 5
  • Maximum Value: 1440
  • Relationship with Focal Device: Sent from each appliance unless "Use only focal appliance" checkbox is set. If so, forwards information to Focal Device.
Use Throttling Cache for Property Updates Enable throttling cache for property updates.

Enable caching of property updates to prevent too many host property resolve messages.

  • Default Value: TRUE
Throttling Cache for Property Updates Timeout (seconds) Time interval (in seconds) to expire properties from throttling cache.

How long property updates are kept in cache.

  • Default Value: 60
  • Minimum Value: 60
  • Maximum Value: 86400
Plugin Configurations Upload Interval (minutes) Interval for uploading plugin configurations to the Cloud (in minutes).

How often to upload plugin configurations to cloud.

  • Default Value: 1440
  • Minimum Value: 15
  • Maximum Value: 10080
  • Relationship with Focal Device: Sent from each appliance unless "Use only focal appliance" checkbox is set. If so, forwards information to Focal Device.
Plugin Configurations Max Message Size (bytes) Max number of bytes that a non-focal device can send to the focal device in a single message during the plugin configuration upload.

This value is both the max message size between non-focal devices and the focal device, as well as the max upload size for plugin configurations.

  • Default Value: 32768
  • Minimum Value: 1024
  • Maximum Value: 65536
Max Size for Message from Non-focal Device to Focal Device (bytes) Max number of bytes that a non-focal device can send to the focal device in a single message during the run of SyncHostnamesTask.
  • Default Value: 32768
  • Minimum Value: 1024
  • Maximum Value: 65536
Max Size for Message from Focal device to Non-focal Device (bytes) Max number of bytes that a focal device can send to the non-focal device in single message about IRD assets that is has polled from Cloud.
  • Default Value: 32768
  • Minimum Value: 1024
  • Maximum Value: 65536
Maximum Payload Size for DICOM Events (KB) Specify the maximum payload size for DICOM events upload (in KB).

The maximum payload size for DICOM events upload (in kilobytes). The max set by cloud is 2 mb.

  • Default Value: 1500
  • Minimum Value: 1000
  • Maximum Value: 2000
DICOM Events Upload Interval (minutes) DICOM events upload interval (in minutes).

How often to upload DICOM events to cloud.

  • Default Value: 30
  • Minimum Value: 15
  • Maximum Value: 1440
  • Relationship with Focal Device: Sent from each appliance unless "Use only focal appliance" checkbox is set. If so, forwards information to Focal Device.
Advanced Compliance Uploads Enabled Enables the Advanced Compliance plugin to upload SCAP reports. If enabled, the CDE plugin will provide the Advanced Compliance plugin with the necessary information to communicate with Forescout Cloud.
  • Config Prop Name: config.advanced_compliance_uploads_enabled.value
  • Default Value: FALSE
Advanced Compliance Upload Interval (mintues) If Advanced Compliance Uploads are enabled, this is the interval at which the Advanced Compliance plugin will attempt to upload reports to Forescout Cloud.
  • Config Prop Name: config.advanced_compliance_uploads_interval.value
  • Default Value: 10
  • Minimum Value: 5
  • Maximum Value: 60
Advanced Compliance Upload Maximum Reports If Advanced Compliance Uploads are enabled, this is maximum number of reports the Advanced Compliance plugin will attempt to upload at once to Forescout Cloud.
  • Config Prop Name: config.advanced_compliance_uploads_max_reports.value
  • Default Value: 200
  • Minimum Value: 50
  • Maximum Value: 500
Advanced Compliance Upload Max Size (MB) If Advanced Compliance Uploads are enabled, this is maximum upload size Advanced Compliance plugin will attempt to upload at once to Forescout Cloud.
  • Config Prop Name: config.advanced_compliance_uploads_max_size.value
  • Default Value: 50
  • Minimum Value: 25
  • Maximum Value: 100
Unmonitored IPs Upload Interval (minutes) Unmonitored IPs upload interval (in minutes).

How often to upload unmonitored IPs to cloud.

  • Default Value: 1440
  • Minimum Value: 720
  • Maximum Value: 1440
  • Relationship with Focal Device: Sent from each appliance unless "Use only focal appliance" checkbox is set. If so, forwards information to Focal Device.
Sync Hostname Interval (minutes) Set how often (in minutes) to sync hostnames and IP maps.

How often to sync known host name cache.

  • Default Value: 15
  • Minimum Value: 15
  • Maximum Value: 60
Cloud Connectivity Interval (minutes) Set how often (in minutes) to check cloud connectivity.

How often to check if CDE is connected to cloud tenant.

  • Default Value: 10
  • Minimum Value: 1
  • Maximum Value: 1440
HTTP Request Timeout (seconds) HTTP request timeout (in seconds).

Default connection timeout for cloud connection.

  • Default Value: 30
  • Minimum Value: 5
  • Maximum Value: 60

Advanced Polling Settings

Requests Polling Interval (minutes)

Specify the time interval (in minutes) for polling the cloud instance for requests.

The time interval (in minutes) for polling the cloud instance for requests for uploads.

  • Default Value: 15
  • Minimum Value: 15
  • Maximum Value: 1440
  • Relationship with Focal Device: Always sent from the Focal Device, even if the "Use only focal appliance" checkbox isn't set.
Enable Detection Polling Enable polling the cloud instance for detections.

Previously detection polling was disabled by setting detection polling interval to 0. This property replaces the enable/disable functionality of that property.

  • Default Value: TRUE
Detection Polling Interval (minutes) Specify the time interval (in minutes) for polling the cloud instance for detections.
  • Default Value: 15
  • Minimum Value: 15
  • Maximum Value: 1440
  • Relationship with Focal Device: Always sent from the Focal Device, even if the "Use only focal appliance" checkbox isn't set.
Enable Assets Polling

Enable polling the cloud instance for asset properties.

Previously asset polling was disabled by setting asset polling interval to 0. This property replaces the enable/disable functionality of that property.

  • Default Value: TRUE
Assets Polling Interval (minutes)

Specify the time interval (in minutes) for polling the cloud instance for asset properties.

  • Default Value: 15
  • Minimum Value: 15
  • Maximum Value: 1440
  • Poll happens from each appliance unless "Use only focal appliance" checkbox is set. If so, only the focal will poll.

Enable Fast Asset Polling

Enable fast polling the cloud instance for asset properties. This only applies for device_tunnel_status, which is a property only available from integration with Netskope.

  • Default Value: TRUE
Fast Asset Polling Interval (minutes)

Specify the time interval (in minutes) for fast polling the cloud instance for asset properties.

  • Default Value: 1
  • Minimum Value: 1
  • Maximum Value: 15
  • Relationship with Focal Device: Poll happens from each appliance unless "Use only focal appliance" checkbox is set. If so, only the focal will poll.

Advanced Assets Settings

Asset Data Upload Interval (minutes) Specify the time interval (in minutes) to upload updated asset data.

The time interval (in minutes) to upload updated asset data.

  • Default Value: 360
  • Minimum Value: 60
  • Maximum Value: 1440
  • Relationship with Focal Device: Sent from each appliance unless "Use only focal appliance" checkbox is set. If so, forwards information to Focal Device.
Allow eyeFocus Admissions Used to determine whether CDE should try and admit assets it has polled from Cloud that do not already exist in eyeSight.
Please see Important Consideration for further details.
  • Default Value: FALSE

Allow eyeFocus MAC Only Admissions

Used to determine whether CDE should try and admit MAC-only assets it has polled from Cloud that do not already exist in eyeSight.

  • Default Value: FALSE
Upload New Asset Data Enable uploading asset data that has been updated.
  • Default Value: TRUE
New Asset Upload Interval (minutes) Specify the time interval (in minutes) for uploading new assets to the cloud instance.

The time interval (in minutes) for uploading new assets to the cloud instance.

  • Default Value: 15
  • Minimum Value: 15
  • Maximum Value: 1440
  • Relationship with Focal Device: Sent from each appliance unless "Use only focal appliance" checkbox is set. If so, forwards information to Focal Device.
Initial assets' properties last updated time (days) Enter the initial value (in days) for the last time asset properties were updated.

Initialize value for assets' properties last updated time. Value will be overwritten when assets' properties are updated.

  • Default Value: 90
  • Minimum Value: 1
  • Maximum Value: 90
Ignore Send2Cysiv Policy Action Ignore Send2Cysiv Policy Action.
  • Default Value: TRUE

Advanced Flow Settings

Enable Flow Uploads Specify whether flows should be uploaded or not.

Whether flows should be uploaded or not.

  • Default Value: TRUE
Maximum Payload Chunk Size for Flows Upload (KB) Specify the maximum payload chunk size for flows upload (in kB).

The maximum payload chunk size for flows upload (in kilobytes). The max set by cloud is 2 mb.

  • Default Value: 1500
  • Minimum Value: 1000
  • Maximum Value: 2000
Enable Packet Engine Flow Heuristics Enable Packet Engine flow heuristics.
  • Default Value: TRUE
Aggregate Inbound Flows Allow aggregating inbound flow sessions to be included in flows upload.
  • Default Value: TRUE
Aggregate Outbound Flows Allow aggregating outbound flow sessions to be included in flows upload.
  • Default Value: TRUE
Aggregate Internal Flows Allow aggregating internal flow sessions to be included in flows upload.
  • Default Value: TRUE
Aggregate External Flows Allow aggregating external flow sessions to be included in flow upload.
  • Default Value: TRUE
Ignore Inbound Flows Ignore inbound flows.
  • Default Value: FALSE
Ignore Outbound Flows Ignore outbound flows.
  • Default Value: TRUE
Ignore TCP Non-bidirectional Flows Ignore TCP non-bidirectional flows.
  • Default Value: TRUE
Ignore UDP Flows With High Ports from eyeSight Ignore UDP flows with high ports from eyeSight.
  • Default Value: TRUE
Ignore UDP Flows from eyeSight Above Port Specify the lowest port from eyeSight to be considered a high UDP port. All flows above this port will be ignored.

All UDP flows that have a source port above this value will be ignored.

  • Default Value: 25000
  • Minimum Value: 20000
  • Maximum Value: 65535
Max Flows to Flush from Flow Connections Table (thousands) Set the max amount of flows (in thousands of flows) to flush from flow connections table. If Dynamic RAM Allocation is enabled, this value is ignored.

The max amount of flows (in thousands of flows) to flush from flow connections table. If Dynamic RAM Allocation is enabled, this value is ignored.

  • Default Value: 1000
  • Minimum Value: 100
  • Maximum Value: 1000
Flow Connections Table Flush Interval (minutes) Specify the time interval (in minutes) to flush the flow connections table.

How often to flush the flow connections table.

  • Default Value: 10
  • Minimum Value: 1
  • Maximum Value: 1440
Flow Upload Interval (seconds) Specify the time interval (in seconds) to send the flow connections table to uploader.

How often to send the flow connections table to uploader.

  • Default Value: 1
  • Minimum Value: 1
  • Maximum Value: 300
  • Relationship with Focal Device: Ignores the Focal Device. Always sent from each eyeSight Device, even if the "Use Focal Device" checkbox is set.
Flow Upload Retries Set the maximum number of times to retry uploading flows.

The maximum number of times to retry uploading flows to cloud.

  • Default Value: 3
  • Minimum Value: 1
  • Maximum Value: 10
Flow Upload Time Between Retries (minutes) Specify the time (in minutes) before retrying to upload flows.

How long to wait before retrying to upload flows.

  • Default Value: 2
  • Minimum Value: 1
  • Maximum Value: 5
Allow Dynamic RAM Allocation for Flows Enable Dynamic RAM allocation for flow connections table in memory.
  • Default Value: TRUE
Flow Size (bytes) Set the size of a single flow (in bytes) in flow connections table.

The size of a single flow (in bytes) in flow connections table. When dynamic RAM allocation is enabled, this value is used, along with how many flows to upload and size of safety buffer, to calculate how much memory to allocate.

  • Default Value: 120
  • Minimum Value: 120
  • Maximum Value: 1000
Number of Flows (MB) Set the size of safety buffer for flow connections table (in mB).

Set the size of safety buffer for flow connections table (in kb). When dynamic RAM allocation is enabled, this value is used, along with how many flows to upload and size of safety buffer, to calculate how much memory to allocate.

  • Default Value: 367
  • Minimum Value: 1
  • Maximum Value: 1000