<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Hit Count Analyzer - FMC 6.6.1 in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/hit-count-analyzer-fmc-6-6-1/m-p/4284657#M1078018</link>
    <description>&lt;P&gt;Apologies - i may have mixed things here, Logging is different and hit count is different.&lt;/P&gt;
&lt;P&gt;Hit count based on the ACP policies matched and processed.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/326046"&gt;@Marvin Rhoads&lt;/a&gt;&amp;nbsp; is right and corrected.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 02 Feb 2021 20:12:36 GMT</pubDate>
    <dc:creator>balaji.bandi</dc:creator>
    <dc:date>2021-02-02T20:12:36Z</dc:date>
    <item>
      <title>Hit Count Analyzer - FMC 6.6.1</title>
      <link>https://community.cisco.com/t5/network-security/hit-count-analyzer-fmc-6-6-1/m-p/4280992#M1077726</link>
      <description>&lt;P&gt;When I run the hitcount analyzer for an ACP and export it to a CSV, the rules with 0 hit counts do not have a date indicating they were never used. Is this the expected behavior? For some of the rules with 0, I imagine they were used at some point, but I can't tell with the date missing from the result.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Jan 2021 22:46:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/hit-count-analyzer-fmc-6-6-1/m-p/4280992#M1077726</guid>
      <dc:creator>Scott_22</dc:creator>
      <dc:date>2021-01-27T22:46:29Z</dc:date>
    </item>
    <item>
      <title>Re: Hit Count Analyzer - FMC 6.6.1</title>
      <link>https://community.cisco.com/t5/network-security/hit-count-analyzer-fmc-6-6-1/m-p/4281015#M1077728</link>
      <description>&lt;P&gt;have you enabled the Log for that ACP, If so please check with the command?&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/102965i488D2510E3606CDA/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can also test from FTD :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;show access-control-config&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Jan 2021 23:38:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/hit-count-analyzer-fmc-6-6-1/m-p/4281015#M1077728</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2021-01-27T23:38:34Z</dc:date>
    </item>
    <item>
      <title>Re: Hit Count Analyzer - FMC 6.6.1</title>
      <link>https://community.cisco.com/t5/network-security/hit-count-analyzer-fmc-6-6-1/m-p/4281488#M1077761</link>
      <description>&lt;P&gt;Yes, logging is enabled at the end of the connection.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 28 Jan 2021 16:02:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/hit-count-analyzer-fmc-6-6-1/m-p/4281488#M1077761</guid>
      <dc:creator>Scott_22</dc:creator>
      <dc:date>2021-01-28T16:02:41Z</dc:date>
    </item>
    <item>
      <title>Re: Hit Count Analyzer - FMC 6.6.1</title>
      <link>https://community.cisco.com/t5/network-security/hit-count-analyzer-fmc-6-6-1/m-p/4281555#M1077766</link>
      <description>&lt;P&gt;Can you post the output from command level and GUI to see what is wrong?&lt;/P&gt;</description>
      <pubDate>Thu, 28 Jan 2021 17:22:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/hit-count-analyzer-fmc-6-6-1/m-p/4281555#M1077766</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2021-01-28T17:22:10Z</dc:date>
    </item>
    <item>
      <title>Re: Hit Count Analyzer - FMC 6.6.1</title>
      <link>https://community.cisco.com/t5/network-security/hit-count-analyzer-fmc-6-6-1/m-p/4281711#M1077789</link>
      <description>&lt;P&gt;What output are you looking for? When I run the hit count analyzer, there is not an entry in the "last hit time" field for hit counts of 0. The same is true from the CLI.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 28 Jan 2021 20:58:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/hit-count-analyzer-fmc-6-6-1/m-p/4281711#M1077789</guid>
      <dc:creator>Scott_22</dc:creator>
      <dc:date>2021-01-28T20:58:00Z</dc:date>
    </item>
    <item>
      <title>Re: Hit Count Analyzer - FMC 6.6.1</title>
      <link>https://community.cisco.com/t5/network-security/hit-count-analyzer-fmc-6-6-1/m-p/4284405#M1078002</link>
      <description>&lt;P&gt;Also to note, I have found rules with an incremented hitaount that do not have logging enabled. Are you sure enabling logging pertains to the hit count analyzer?&lt;/P&gt;</description>
      <pubDate>Tue, 02 Feb 2021 15:50:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/hit-count-analyzer-fmc-6-6-1/m-p/4284405#M1078002</guid>
      <dc:creator>Scott_22</dc:creator>
      <dc:date>2021-02-02T15:50:53Z</dc:date>
    </item>
    <item>
      <title>Re: Hit Count Analyzer - FMC 6.6.1</title>
      <link>https://community.cisco.com/t5/network-security/hit-count-analyzer-fmc-6-6-1/m-p/4284445#M1078008</link>
      <description>&lt;P&gt;Hit counts will increment independent of logging being set. Logging will additionally generate a syslog message.&lt;/P&gt;
&lt;P&gt;Hit counts are not retained across a reboot so a zero count is implicitly "since last boot" (or manual clear of the counts).&lt;/P&gt;
&lt;P&gt;Reference (from ASA but the same logic applies): &lt;A href="https://www.cisco.com/c/en/us/td/docs/security/asa/asa-cli-reference/A-H/asa-command-ref-A-H/aa-ac-commands.html#wp3307265190" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/asa/asa-cli-reference/A-H/asa-command-ref-A-H/aa-ac-commands.html#wp3307265190&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;TABLE border="1" width="100%"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD&gt;
&lt;P class="p"&gt;&lt;SPAN class="ph synph"&gt;&lt;SPAN class="keyword kwd"&gt;log&lt;/SPAN&gt; &lt;/SPAN&gt; [[&lt;EM class="ph i"&gt;level&lt;/EM&gt; ] [&lt;SPAN class="ph synph"&gt;&lt;SPAN class="keyword kwd"&gt;interval&lt;/SPAN&gt; &lt;/SPAN&gt; &lt;EM class="ph i"&gt;secs&lt;/EM&gt; ] | &lt;SPAN class="ph synph"&gt;&lt;SPAN class="keyword kwd"&gt;disable&lt;/SPAN&gt; &lt;/SPAN&gt; | &lt;SPAN class="ph synph"&gt;&lt;SPAN class="keyword kwd"&gt;default&lt;/SPAN&gt; &lt;/SPAN&gt;]&lt;/P&gt;
&lt;/TD&gt;
&lt;TD&gt;
&lt;P class="p"&gt;(Optional) Sets logging options when an ACE matches a packet for network access (an ACL applied with the &lt;SPAN class="ph synph"&gt;&lt;SPAN class="keyword kwd"&gt;access-group&lt;/SPAN&gt; &lt;/SPAN&gt; command). If you enter the &lt;SPAN class="ph synph"&gt;&lt;SPAN class="keyword kwd"&gt;log&lt;/SPAN&gt; &lt;/SPAN&gt; keyword without any arguments, you enable system log message 106100 at the default level (6) and for the default interval (300 seconds). If you do not enter the &lt;SPAN class="ph synph"&gt;&lt;SPAN class="keyword kwd"&gt;log&lt;/SPAN&gt; &lt;/SPAN&gt; keyword, then the default system log message 106023 is generated for denied packets. Log options are:&lt;/P&gt;
&lt;UL class="ul"&gt;
&lt;LI class="li"&gt;
&lt;P class="p"&gt;&lt;EM class="ph i"&gt;level&lt;/EM&gt; —A severity level between 0 and 7. The default is 6 (informational). If you change this level for an active ACE, the new level applies to new connections; existing connections continue to be logged at the previous level.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI class="li"&gt;
&lt;P class="p"&gt;&lt;SPAN class="ph synph"&gt;&lt;SPAN class="keyword kwd"&gt;interval&lt;/SPAN&gt; &lt;/SPAN&gt;&lt;EM class="ph i"&gt;secs&lt;/EM&gt; —The time interval in seconds between syslog messages, from 1 to 600. The default is 300. This value is also used as the timeout value for deleting an inactive flow from the cache used to collect drop statistics.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI class="li"&gt;
&lt;P class="p"&gt;&lt;SPAN class="ph synph"&gt;&lt;SPAN class="keyword kwd"&gt;disable&lt;/SPAN&gt; &lt;/SPAN&gt;—Disables all ACE logging.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI class="li"&gt;
&lt;P class="p"&gt;&lt;SPAN class="ph synph"&gt;&lt;SPAN class="keyword kwd"&gt;default&lt;/SPAN&gt; &lt;/SPAN&gt;—Enables logging to message 106023. This setting is the same as not including the &lt;SPAN class="ph synph"&gt;&lt;SPAN class="keyword kwd"&gt;log&lt;/SPAN&gt; &lt;/SPAN&gt; option.&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;</description>
      <pubDate>Tue, 02 Feb 2021 16:27:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/hit-count-analyzer-fmc-6-6-1/m-p/4284445#M1078008</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2021-02-02T16:27:02Z</dc:date>
    </item>
    <item>
      <title>Re: Hit Count Analyzer - FMC 6.6.1</title>
      <link>https://community.cisco.com/t5/network-security/hit-count-analyzer-fmc-6-6-1/m-p/4284633#M1078017</link>
      <description>&lt;P&gt;Thank you for clarifying! The previous comment was misleading around how logging should be enabled.&lt;/P&gt;</description>
      <pubDate>Tue, 02 Feb 2021 19:36:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/hit-count-analyzer-fmc-6-6-1/m-p/4284633#M1078017</guid>
      <dc:creator>Scott_22</dc:creator>
      <dc:date>2021-02-02T19:36:27Z</dc:date>
    </item>
    <item>
      <title>Re: Hit Count Analyzer - FMC 6.6.1</title>
      <link>https://community.cisco.com/t5/network-security/hit-count-analyzer-fmc-6-6-1/m-p/4284657#M1078018</link>
      <description>&lt;P&gt;Apologies - i may have mixed things here, Logging is different and hit count is different.&lt;/P&gt;
&lt;P&gt;Hit count based on the ACP policies matched and processed.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/326046"&gt;@Marvin Rhoads&lt;/a&gt;&amp;nbsp; is right and corrected.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 02 Feb 2021 20:12:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/hit-count-analyzer-fmc-6-6-1/m-p/4284657#M1078018</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2021-02-02T20:12:36Z</dc:date>
    </item>
  </channel>
</rss>

