<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FMC connectivity log shows blank action and reason columns in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/fmc-connectivity-log-shows-blank-action-and-reason-columns/m-p/5209745#M1116621</link>
    <description>&lt;P&gt;Was this working previously? What version is your FMC?&lt;/P&gt;
&lt;P&gt;Can you check Analysis &amp;gt; Unified Events (assuming you are at 7.2+) and see what it shows?&lt;/P&gt;</description>
    <pubDate>Wed, 16 Oct 2024 16:11:46 GMT</pubDate>
    <dc:creator>Marvin Rhoads</dc:creator>
    <dc:date>2024-10-16T16:11:46Z</dc:date>
    <item>
      <title>FMC connectivity log shows blank action and reason columns</title>
      <link>https://community.cisco.com/t5/network-security/fmc-connectivity-log-shows-blank-action-and-reason-columns/m-p/5209735#M1116619</link>
      <description>&lt;P&gt;I am seeing quite a large amount of connectivity events in the FMC with blank/empty fields for action and reason.&amp;nbsp; What does this mean?&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;TIA,&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="FMC-log.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/231441i16923538ADDD91AC/image-size/medium?v=v2&amp;amp;px=400" role="button" title="FMC-log.png" alt="FMC-log.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 16 Oct 2024 15:53:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-connectivity-log-shows-blank-action-and-reason-columns/m-p/5209735#M1116619</guid>
      <dc:creator>tato386</dc:creator>
      <dc:date>2024-10-16T15:53:30Z</dc:date>
    </item>
    <item>
      <title>Re: FMC connectivity log shows blank action and reason columns</title>
      <link>https://community.cisco.com/t5/network-security/fmc-connectivity-log-shows-blank-action-and-reason-columns/m-p/5209745#M1116621</link>
      <description>&lt;P&gt;Was this working previously? What version is your FMC?&lt;/P&gt;
&lt;P&gt;Can you check Analysis &amp;gt; Unified Events (assuming you are at 7.2+) and see what it shows?&lt;/P&gt;</description>
      <pubDate>Wed, 16 Oct 2024 16:11:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-connectivity-log-shows-blank-action-and-reason-columns/m-p/5209745#M1116621</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2024-10-16T16:11:46Z</dc:date>
    </item>
    <item>
      <title>Re: FMC connectivity log shows blank action and reason columns</title>
      <link>https://community.cisco.com/t5/network-security/fmc-connectivity-log-shows-blank-action-and-reason-columns/m-p/5209771#M1116627</link>
      <description>&lt;P&gt;The unified events screen seems consistent with connectivity log.&amp;nbsp; Most events look normal with a value for action and reason but there seems to be quite a few that are blank for both.&amp;nbsp; I've attached more examples&lt;/P&gt;</description>
      <pubDate>Wed, 16 Oct 2024 16:53:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-connectivity-log-shows-blank-action-and-reason-columns/m-p/5209771#M1116627</guid>
      <dc:creator>tato386</dc:creator>
      <dc:date>2024-10-16T16:53:08Z</dc:date>
    </item>
    <item>
      <title>Re: FMC connectivity log shows blank action and reason columns</title>
      <link>https://community.cisco.com/t5/network-security/fmc-connectivity-log-shows-blank-action-and-reason-columns/m-p/5210017#M1116636</link>
      <description>&lt;P&gt;That is certainly odd and not what we would expect. What version is your FMC?&lt;/P&gt;
&lt;P&gt;I would suggest trying to simulate one of the observed connection events with packet-tracer and seeing what the verdict is there.&lt;/P&gt;</description>
      <pubDate>Thu, 17 Oct 2024 06:10:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-connectivity-log-shows-blank-action-and-reason-columns/m-p/5210017#M1116636</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2024-10-17T06:10:07Z</dc:date>
    </item>
    <item>
      <title>Re: FMC connectivity log shows blank action and reason columns</title>
      <link>https://community.cisco.com/t5/network-security/fmc-connectivity-log-shows-blank-action-and-reason-columns/m-p/5211321#M1116749</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/326046"&gt;@Marvin Rhoads&lt;/a&gt;&amp;nbsp;do you know if it's possible to search for null or blank fields in the connectivity logs?&amp;nbsp; I tried null, $null, {null} but none seem to work.&lt;/P&gt;</description>
      <pubDate>Fri, 18 Oct 2024 19:44:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-connectivity-log-shows-blank-action-and-reason-columns/m-p/5211321#M1116749</guid>
      <dc:creator>tato386</dc:creator>
      <dc:date>2024-10-18T19:44:55Z</dc:date>
    </item>
    <item>
      <title>Re: FMC connectivity log shows blank action and reason columns</title>
      <link>https://community.cisco.com/t5/network-security/fmc-connectivity-log-shows-blank-action-and-reason-columns/m-p/5211360#M1116757</link>
      <description>&lt;P&gt;Are you logging only at the end of a connection, or both at the start and end, for the access-rule that's related to this traffic?&lt;BR /&gt;And when you're viewing the logs, are these the latest logs or are you viewing events back in time?&lt;/P&gt;
&lt;P&gt;The reason I'm asking, I'm wondering if you could be hitting a scenario where initial packets have been allowed through based on an application allow rule, but not enough packets have been transmitted for the firewall to determine the application, and therefore determine if the session should be allowed or blocked, and if you're viewing in real time the session hasn't timed out yet. (Schrodinger's session?)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 18 Oct 2024 22:40:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-connectivity-log-shows-blank-action-and-reason-columns/m-p/5211360#M1116757</guid>
      <dc:creator>Jonatan Jonasson</dc:creator>
      <dc:date>2024-10-18T22:40:47Z</dc:date>
    </item>
    <item>
      <title>Re: FMC connectivity log shows blank action and reason columns</title>
      <link>https://community.cisco.com/t5/network-security/fmc-connectivity-log-shows-blank-action-and-reason-columns/m-p/5211430#M1116758</link>
      <description>&lt;P&gt;In Unified Events, try !N/A. That seems to work for me in FMC 7.6. (That same syntax does not work in Analysis of Connection Events.)&lt;/P&gt;
&lt;P&gt;You could also exclude all of the other actions since there are only 4-5 possible ones (Allow, Block, Trust, Monitor, Fastpath off the top of my head)&lt;/P&gt;</description>
      <pubDate>Sat, 19 Oct 2024 08:35:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-connectivity-log-shows-blank-action-and-reason-columns/m-p/5211430#M1116758</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2024-10-19T08:35:32Z</dc:date>
    </item>
    <item>
      <title>Re: FMC connectivity log shows blank action and reason columns</title>
      <link>https://community.cisco.com/t5/network-security/fmc-connectivity-log-shows-blank-action-and-reason-columns/m-p/5211578#M1116759</link>
      <description>&lt;P&gt;I noticed that the events with no action did not have data in URL column either.&amp;nbsp; I thought this odd since these events where being successfully decrypted with resign and this requires a FQDN for cert name.&lt;/P&gt;&lt;P&gt;I added a rule to not decrypt traffic to one particular destination IP that showed up quite a bit and the results are posted below.&amp;nbsp; As soon as decrypt was off both the action and URL began to show data.&amp;nbsp; I guess we're looking at a bug.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="FMC-ActionURLDecrypt.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/231802i992B775309B1B6A9/image-size/large?v=v2&amp;amp;px=999" role="button" title="FMC-ActionURLDecrypt.png" alt="FMC-ActionURLDecrypt.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 19 Oct 2024 19:41:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-connectivity-log-shows-blank-action-and-reason-columns/m-p/5211578#M1116759</guid>
      <dc:creator>tato386</dc:creator>
      <dc:date>2024-10-19T19:41:54Z</dc:date>
    </item>
    <item>
      <title>Re: FMC connectivity log shows blank action and reason columns</title>
      <link>https://community.cisco.com/t5/network-security/fmc-connectivity-log-shows-blank-action-and-reason-columns/m-p/5217172#M1117097</link>
      <description>&lt;P&gt;same as what I think&amp;nbsp;&lt;BR /&gt;cisco make good table when you use log in end or start of connection&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot (861).png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/232685i31DDB12EE8E61ACC/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot (861).png" alt="Screenshot (861).png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Oct 2024 07:22:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-connectivity-log-shows-blank-action-and-reason-columns/m-p/5217172#M1117097</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-10-30T07:22:05Z</dc:date>
    </item>
    <item>
      <title>Re: FMC connectivity log shows blank action and reason columns</title>
      <link>https://community.cisco.com/t5/network-security/fmc-connectivity-log-shows-blank-action-and-reason-columns/m-p/5217370#M1117116</link>
      <description>&lt;P&gt;TAC pointed out this bug&amp;nbsp;&lt;A href="https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvs50538" target="_blank"&gt;https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvs50538&lt;/A&gt;&amp;nbsp;but it only references older software versions and I am at v7.4.2&lt;/P&gt;</description>
      <pubDate>Wed, 30 Oct 2024 12:34:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-connectivity-log-shows-blank-action-and-reason-columns/m-p/5217370#M1117116</guid>
      <dc:creator>tato386</dc:creator>
      <dc:date>2024-10-30T12:34:47Z</dc:date>
    </item>
    <item>
      <title>Re: FMC connectivity log shows blank action and reason columns</title>
      <link>https://community.cisco.com/t5/network-security/fmc-connectivity-log-shows-blank-action-and-reason-columns/m-p/5217854#M1117149</link>
      <description>&lt;P&gt;you use SSL policy so you need to change Log to be end of connection&amp;nbsp;&lt;BR /&gt;log can not know the IP and detail of packet if it encrypt&amp;nbsp;&lt;/P&gt;
&lt;P&gt;so FTD need to decrypt the packet then list the info&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 31 Oct 2024 06:59:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-connectivity-log-shows-blank-action-and-reason-columns/m-p/5217854#M1117149</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-10-31T06:59:50Z</dc:date>
    </item>
    <item>
      <title>Re: FMC connectivity log shows blank action and reason columns</title>
      <link>https://community.cisco.com/t5/network-security/fmc-connectivity-log-shows-blank-action-and-reason-columns/m-p/5218109#M1117174</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1065752"&gt;@MHM Cisco World&lt;/a&gt;&amp;nbsp;yes, all my polices use "log at end" but this does not prevent the issue from occuring&lt;/P&gt;</description>
      <pubDate>Thu, 31 Oct 2024 13:52:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-connectivity-log-shows-blank-action-and-reason-columns/m-p/5218109#M1117174</guid>
      <dc:creator>tato386</dc:creator>
      <dc:date>2024-10-31T13:52:27Z</dc:date>
    </item>
    <item>
      <title>Re: FMC connectivity log shows blank action and reason columns</title>
      <link>https://community.cisco.com/t5/network-security/fmc-connectivity-log-shows-blank-action-and-reason-columns/m-p/5218210#M1117186</link>
      <description>&lt;P&gt;OK&amp;nbsp;&lt;/P&gt;
&lt;P&gt;the default action of ssl policy is set with log ?&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Thu, 31 Oct 2024 16:14:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-connectivity-log-shows-blank-action-and-reason-columns/m-p/5218210#M1117186</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-10-31T16:14:51Z</dc:date>
    </item>
    <item>
      <title>Re: FMC connectivity log shows blank action and reason columns</title>
      <link>https://community.cisco.com/t5/network-security/fmc-connectivity-log-shows-blank-action-and-reason-columns/m-p/5218652#M1117213</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1065752"&gt;@MHM Cisco World&lt;/a&gt;&amp;nbsp;, the events in question were not matching the default action, they were clearly matching a decrypt-resign rule that has always been enabled for log at end.&amp;nbsp; Nevertheless, I checked default action and enabled log at end.&amp;nbsp; I don't expect this to make a difference but who knows, stranger things have happened.&amp;nbsp; I will post back if this makes any difference.&lt;/P&gt;</description>
      <pubDate>Fri, 01 Nov 2024 15:36:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-connectivity-log-shows-blank-action-and-reason-columns/m-p/5218652#M1117213</guid>
      <dc:creator>tato386</dc:creator>
      <dc:date>2024-11-01T15:36:59Z</dc:date>
    </item>
    <item>
      <title>Re: FMC connectivity log shows blank action and reason columns</title>
      <link>https://community.cisco.com/t5/network-security/fmc-connectivity-log-shows-blank-action-and-reason-columns/m-p/5218780#M1117243</link>
      <description>&lt;P&gt;Yes I believe this is something that could be caused by a Connection that has ended prior to getting fully evaluated by the firewall logic in the Access Control Rules. For example, if you are doing a Decrypt/Resign and the client ended the connection due to an invalid SSL certificate.&lt;/P&gt;
&lt;P&gt;Feel free to open a TAC case around this for some more information around the screenshot/logs you have presented here.&lt;/P&gt;</description>
      <pubDate>Fri, 01 Nov 2024 19:48:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-connectivity-log-shows-blank-action-and-reason-columns/m-p/5218780#M1117243</guid>
      <dc:creator>ckleopa</dc:creator>
      <dc:date>2024-11-01T19:48:33Z</dc:date>
    </item>
  </channel>
</rss>

