<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic FireSight no receiving data from FirePower in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/firesight-no-receiving-data-from-firepower/m-p/3046748#M1017017</link>
    <description>&lt;P&gt;I have 2 cisco ASA 5525-X which I had disable the policy to send traffic to firepower like 1 month ago because i was having high CPU and memory issue, now I re-apply the policy and I have 2 days with the policy up and there is not data on the FireSight center and i can see everything is normal.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can someone give me a hand here?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/media/firepower1.jpg" class="migrated-markup-image" /&gt;&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/media/firepower.jpg" class="migrated-markup-image" /&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 13:17:03 GMT</pubDate>
    <dc:creator>sistematico</dc:creator>
    <dc:date>2019-03-12T13:17:03Z</dc:date>
    <item>
      <title>FireSight no receiving data from FirePower</title>
      <link>https://community.cisco.com/t5/network-security/firesight-no-receiving-data-from-firepower/m-p/3046748#M1017017</link>
      <description>&lt;P&gt;I have 2 cisco ASA 5525-X which I had disable the policy to send traffic to firepower like 1 month ago because i was having high CPU and memory issue, now I re-apply the policy and I have 2 days with the policy up and there is not data on the FireSight center and i can see everything is normal.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can someone give me a hand here?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/media/firepower1.jpg" class="migrated-markup-image" /&gt;&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/media/firepower.jpg" class="migrated-markup-image" /&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 13:17:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firesight-no-receiving-data-from-firepower/m-p/3046748#M1017017</guid>
      <dc:creator>sistematico</dc:creator>
      <dc:date>2019-03-12T13:17:03Z</dc:date>
    </item>
    <item>
      <title>try to install the latest</title>
      <link>https://community.cisco.com/t5/network-security/firesight-no-receiving-data-from-firepower/m-p/3046749#M1017019</link>
      <description>&lt;P&gt;try to install the latest code to use&amp;nbsp;all new features with the device.After the proper installation and having all the required license including Firesight host license you need to make sure that the traffic has been properly redirected to pass through the Firepower.If the Firepower is redirecting the traffic you can see the same by enabling the logging under the access control policy by Policies &amp;gt; Access Control &amp;gt; Rules &amp;gt; Logging &amp;gt; Logging at beginning of connection or&amp;nbsp;&lt;SPAN&gt;Logging at end&amp;nbsp;of connection . Once after enabling logging, save and reapply or redeploy the policy changes. Each device has its own database connection settings. So you can refer the following link and see how much of events can be logged in the device.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;A href="http://www.cisco.com/c/en/us/td/docs/security/firesight/541/user-guide/FireSIGHT-System-UserGuide-v5401/System-Policy.html#pgfId-8018593"&gt;http://www.cisco.com/c/en/us/td/docs/security/firesight/541/user-guide/F...&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;If you can see the respective connection events under Analysis &amp;gt; Connection Events , the dashboard data also should populate . If you already enabled the above and still no events are coming up then please perform the following by the login to Firesight CLI by elevating to root user.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;1) Verify the following service is running&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;pmtool status | grep&amp;nbsp;SFTop10Cacher&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;2) Restart the service&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;pmtool restartbyid&amp;nbsp;&amp;nbsp;SFTop10Cacher&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;3) You should see the service as running with a different pid&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;pmtool status | grep&amp;nbsp;SFTop10Cacher&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Verify the dashboard after 30 minutes.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 09 Feb 2017 21:15:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firesight-no-receiving-data-from-firepower/m-p/3046749#M1017019</guid>
      <dc:creator>Farhan Mohamed</dc:creator>
      <dc:date>2017-02-09T21:15:34Z</dc:date>
    </item>
    <item>
      <title>I fixed it by rebooting the</title>
      <link>https://community.cisco.com/t5/network-security/firesight-no-receiving-data-from-firepower/m-p/3046750#M1017021</link>
      <description>&lt;P&gt;I fixed it by rebooting the defence center&lt;/P&gt;</description>
      <pubDate>Fri, 10 Feb 2017 16:54:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firesight-no-receiving-data-from-firepower/m-p/3046750#M1017021</guid>
      <dc:creator>sistematico</dc:creator>
      <dc:date>2017-02-10T16:54:25Z</dc:date>
    </item>
  </channel>
</rss>

