<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Any update on this?   in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/firepower-threat-defense-real-time-log-viewer/m-p/2936572#M149253</link>
    <description>&lt;P&gt;Any update on this? &amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;What about AnyConnect VPN Support coming to FTD?&lt;/P&gt;</description>
    <pubDate>Wed, 10 May 2017 16:35:58 GMT</pubDate>
    <dc:creator>Lucas Phelps</dc:creator>
    <dc:date>2017-05-10T16:35:58Z</dc:date>
    <item>
      <title>FirePower Threat Defense Real time log viewer</title>
      <link>https://community.cisco.com/t5/network-security/firepower-threat-defense-real-time-log-viewer/m-p/2936567#M149246</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;In cisco ASDM tool we have a section for real time monitoring the traffic which flow on our device ( monitoring &amp;gt; logging &amp;gt; real time log viewer) in this tab we can monitor all network activity and flow creation and teardown&amp;nbsp; but when we installed FirePower Threat Defense software and add it on Cisco FMC , actually we lost this real time monitoring ,&amp;nbsp; How we can monitor real time log int FMC ? Is there any option on FMC for real time Log viewer just ASA ASDM?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;thanks&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 08:23:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-threat-defense-real-time-log-viewer/m-p/2936567#M149246</guid>
      <dc:creator>jackk.rayen</dc:creator>
      <dc:date>2019-03-12T08:23:45Z</dc:date>
    </item>
    <item>
      <title>I have heard that real-time</title>
      <link>https://community.cisco.com/t5/network-security/firepower-threat-defense-real-time-log-viewer/m-p/2936568#M149249</link>
      <description>&lt;P&gt;I have heard that real-time log view/monitor is coming to FireSIGHT but was never given an actual version. As of right now, this feature is not available.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Sorry to bring the bad news &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Thank you for rating helpful posts!&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 13 Oct 2016 18:34:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-threat-defense-real-time-log-viewer/m-p/2936568#M149249</guid>
      <dc:creator>nspasov</dc:creator>
      <dc:date>2016-10-13T18:34:16Z</dc:date>
    </item>
    <item>
      <title>Sorry but there's not</title>
      <link>https://community.cisco.com/t5/network-security/firepower-threat-defense-real-time-log-viewer/m-p/2936569#M149250</link>
      <description>&lt;P&gt;Sorry but there's not currently any such capability in FMC (or on the sensor itself). It's not in any short term plan either (although customer demand can sometimes result in development resources being allocated sooner).&lt;/P&gt;
&lt;P&gt;The closest you can come right now is to create a syslog server and tail the syslog output.&lt;/P&gt;
&lt;P&gt;There are the cli system support commands you can run that allow you to do packet trace and capture.&lt;/P&gt;
&lt;P&gt;You can also access them via the GUI under System &amp;gt; Health &amp;gt; Monitor &amp;gt; (select device) &amp;gt; Advanced Troubleshooting. FTD devices will have those tools exposed there. (Note you can only do this for FTD devices and only from FMC.)&lt;/P&gt;</description>
      <pubDate>Thu, 13 Oct 2016 23:42:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-threat-defense-real-time-log-viewer/m-p/2936569#M149250</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2016-10-13T23:42:32Z</dc:date>
    </item>
    <item>
      <title>Thanks for your helpful</title>
      <link>https://community.cisco.com/t5/network-security/firepower-threat-defense-real-time-log-viewer/m-p/2936570#M149251</link>
      <description>&lt;P&gt;Thanks for your helpful answer, so we are waiting for the future.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;thanks all&lt;/P&gt;</description>
      <pubDate>Fri, 14 Oct 2016 12:10:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-threat-defense-real-time-log-viewer/m-p/2936570#M149251</guid>
      <dc:creator>jackk.rayen</dc:creator>
      <dc:date>2016-10-14T12:10:36Z</dc:date>
    </item>
    <item>
      <title>You can also use the</title>
      <link>https://community.cisco.com/t5/network-security/firepower-threat-defense-real-time-log-viewer/m-p/2936571#M149252</link>
      <description>&lt;P&gt;You can also use the Connection-&amp;lt; Events tab in FMC. I agree it's not as good as the real time log but it can be very helpful&lt;/P&gt;</description>
      <pubDate>Fri, 14 Oct 2016 19:05:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-threat-defense-real-time-log-viewer/m-p/2936571#M149252</guid>
      <dc:creator>michaellperrin</dc:creator>
      <dc:date>2016-10-14T19:05:27Z</dc:date>
    </item>
    <item>
      <title>Any update on this?  </title>
      <link>https://community.cisco.com/t5/network-security/firepower-threat-defense-real-time-log-viewer/m-p/2936572#M149253</link>
      <description>&lt;P&gt;Any update on this? &amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;What about AnyConnect VPN Support coming to FTD?&lt;/P&gt;</description>
      <pubDate>Wed, 10 May 2017 16:35:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-threat-defense-real-time-log-viewer/m-p/2936572#M149253</guid>
      <dc:creator>Lucas Phelps</dc:creator>
      <dc:date>2017-05-10T16:35:58Z</dc:date>
    </item>
    <item>
      <title>Nothing on the log viewer.</title>
      <link>https://community.cisco.com/t5/network-security/firepower-threat-defense-real-time-log-viewer/m-p/2936573#M149255</link>
      <description>&lt;P&gt;Nothing on the log viewer.&lt;/P&gt;
&lt;P&gt;Remote access SSL VPN (for AnyConnect clients) will be introduced in FirePOWER 6.2.1 for FTD on the FirePOWER 2100 at that product's FCS date (First Customer Ship - sheduled for 22 May last I heard). The remaining FTD platforms will get it in a subsequent release shortly thereafter.&lt;/P&gt;</description>
      <pubDate>Wed, 10 May 2017 16:44:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-threat-defense-real-time-log-viewer/m-p/2936573#M149255</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2017-05-10T16:44:54Z</dc:date>
    </item>
    <item>
      <title>Marvin, I would like to</title>
      <link>https://community.cisco.com/t5/network-security/firepower-threat-defense-real-time-log-viewer/m-p/2936574#M149256</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 14 Nov 2017 07:49:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-threat-defense-real-time-log-viewer/m-p/2936574#M149256</guid>
      <dc:creator>prashant dwivedi</dc:creator>
      <dc:date>2017-11-14T07:49:43Z</dc:date>
    </item>
    <item>
      <title>My understanding is that when</title>
      <link>https://community.cisco.com/t5/network-security/firepower-threat-defense-real-time-log-viewer/m-p/2936575#M149257</link>
      <description>&lt;P&gt;My understanding is that when you have a syslog (or SNMP trap) action as part of a policy that has been deployed to a sensor (FTD or FirePOWER) that the syslog events and SNMP traps originate from the sensor itself.&lt;/P&gt;
&lt;P&gt;See Oliver's response here confirming that behavior:&lt;/P&gt;
&lt;P&gt;https://supportforums.cisco.com/discussion/13251571/firepower-rule-connection-logging-syslog-question&lt;/P&gt;
&lt;P&gt;The FMC will not necessarily show everything that's going on at the sensor - only events that are configured to create event logs will be sent up to FMC.&lt;/P&gt;
&lt;P&gt;FX-OS chassis level logs are certainly useful but only if you have somebody actually watching them or atl least checking them periodically. Few things are less useful than a log entry that nobody sees.&lt;/P&gt;
&lt;P&gt;Regarding backups, see the configuration guide here:&lt;/P&gt;
&lt;P&gt;http://www.cisco.com/c/en/us/td/docs/security/firepower/621/configuration/guide/fpmc-config-guide-v621/backup_and_restore.html&lt;/P&gt;
&lt;P&gt;It notes:&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;&lt;SPAN&gt;You &lt;/SPAN&gt;&lt;STRONG&gt;cannot&lt;/STRONG&gt;&lt;SPAN&gt; create or restore backup files for &lt;/SPAN&gt;&lt;SPAN&gt;NGIPSv&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;SPAN&gt;Firepower Threat Defense&lt;/SPAN&gt; physical or virtual managed devices&lt;/SPAN&gt;&lt;SPAN&gt; or&lt;/SPAN&gt;&lt;SPAN&gt;ASA FirePOWER&lt;/SPAN&gt;&lt;SPAN&gt; modules. To back up event data, perform a backup of the managing &lt;/SPAN&gt;&lt;SPAN&gt;Firepower Management Center&lt;/SPAN&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;...which confirms what you are seeing.&lt;/P&gt;</description>
      <pubDate>Wed, 24 May 2017 08:25:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-threat-defense-real-time-log-viewer/m-p/2936575#M149257</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2017-05-24T08:25:58Z</dc:date>
    </item>
    <item>
      <title>Re: Sorry but there's not</title>
      <link>https://community.cisco.com/t5/network-security/firepower-threat-defense-real-time-log-viewer/m-p/3320748#M149258</link>
      <description>&lt;P&gt;Hello Marvin,&lt;/P&gt;
&lt;P&gt;Need your help /input please.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;On FTDs, we are logging traffic and sending to the external syslog server. we want to see some historical data ( logs ) to troubleshoot any issues.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We noticed FMC is only logging the traffic for last 24 hours, I have increased the database size and hopefully this will increase the data capacity.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Another issue is&amp;nbsp; with sending traffic tot he external syslog server, I want to enable SYSLOG ID - 106100 with logging level as "informaitonal" , idea behind this is to get a log whenever there is any deined traffic at access control policy. however, I am getting error while pushing the policy once have 106100 enabled.&amp;nbsp; Please advise how we could do this in FTD?&amp;nbsp; I have tried using Flexconfig however found the same issue.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;in suammry - we want to have logs at Syslog server , need to know if a traffic is being denied by ACEs , need to the rule that is dropping the traffic.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 29 Jan 2018 08:42:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-threat-defense-real-time-log-viewer/m-p/3320748#M149258</guid>
      <dc:creator>prashant dwivedi</dc:creator>
      <dc:date>2018-01-29T08:42:13Z</dc:date>
    </item>
    <item>
      <title>Re: Sorry but there's not</title>
      <link>https://community.cisco.com/t5/network-security/firepower-threat-defense-real-time-log-viewer/m-p/3339077#M149259</link>
      <description>&lt;P&gt;I find it strange that cisco is not working on sort of viewer like we had on the ASA for the FTD, and for the FMC.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;someone from cisco needs to respond to this thread.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 27 Feb 2018 21:21:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-threat-defense-real-time-log-viewer/m-p/3339077#M149259</guid>
      <dc:creator>Jeffrey Jones</dc:creator>
      <dc:date>2018-02-27T21:21:54Z</dc:date>
    </item>
    <item>
      <title>Re: Sorry but there's not</title>
      <link>https://community.cisco.com/t5/network-security/firepower-threat-defense-real-time-log-viewer/m-p/3379517#M149260</link>
      <description>&lt;P&gt;Im&amp;nbsp;with you, This is unacceptable.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'll bring this up to my local reps and see what the response is.&lt;/P&gt;</description>
      <pubDate>Mon, 07 May 2018 18:53:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-threat-defense-real-time-log-viewer/m-p/3379517#M149260</guid>
      <dc:creator>James_1</dc:creator>
      <dc:date>2018-05-07T18:53:35Z</dc:date>
    </item>
    <item>
      <title>Re: Sorry but there's not</title>
      <link>https://community.cisco.com/t5/network-security/firepower-threat-defense-real-time-log-viewer/m-p/3411316#M149261</link>
      <description>&lt;P&gt;Any updates on this?&lt;/P&gt;</description>
      <pubDate>Fri, 06 Jul 2018 06:23:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-threat-defense-real-time-log-viewer/m-p/3411316#M149261</guid>
      <dc:creator>floulourgas</dc:creator>
      <dc:date>2018-07-06T06:23:10Z</dc:date>
    </item>
    <item>
      <title>Re: Sorry but there's not</title>
      <link>https://community.cisco.com/t5/network-security/firepower-threat-defense-real-time-log-viewer/m-p/3412623#M149262</link>
      <description>&lt;P&gt;You can use the capture command on the CLI of the device same as the ASA.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Example&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Capture in interface inside match ip 192.168.1.0 255.255.255.0 any&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The use the show capture command to see.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 09 Jul 2018 12:42:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-threat-defense-real-time-log-viewer/m-p/3412623#M149262</guid>
      <dc:creator>michaellperrin</dc:creator>
      <dc:date>2018-07-09T12:42:22Z</dc:date>
    </item>
    <item>
      <title>Re: Sorry but there's not</title>
      <link>https://community.cisco.com/t5/network-security/firepower-threat-defense-real-time-log-viewer/m-p/4945025#M1105244</link>
      <description>&lt;P&gt;Hi Marvin what is the best way to view just blocked events or logs? I don't see a parameter under Analysis&amp;gt;Events tab or way under Syslog when viewing on FMC&lt;/P&gt;</description>
      <pubDate>Fri, 20 Oct 2023 13:43:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-threat-defense-real-time-log-viewer/m-p/4945025#M1105244</guid>
      <dc:creator>CiscoBrownBelt</dc:creator>
      <dc:date>2023-10-20T13:43:55Z</dc:date>
    </item>
    <item>
      <title>Re: Sorry but there's not</title>
      <link>https://community.cisco.com/t5/network-security/firepower-threat-defense-real-time-log-viewer/m-p/4945090#M1105250</link>
      <description>&lt;P&gt;When your in the Events window. Click on "Edit search". Then in General Information Type "Block" in the Action field.&lt;BR /&gt;Then Click "Search". That'll show you all the Blocks that are being logged.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Edit Search SS.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/200265iCE72386BAC76021D/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Edit Search SS.png" alt="Edit Search SS.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Edit SS.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/200266i91A6E5CC06D9B25B/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Edit SS.png" alt="Edit SS.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Fri, 20 Oct 2023 14:58:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-threat-defense-real-time-log-viewer/m-p/4945090#M1105250</guid>
      <dc:creator>James_1</dc:creator>
      <dc:date>2023-10-20T14:58:26Z</dc:date>
    </item>
    <item>
      <title>Re: Sorry but there's not</title>
      <link>https://community.cisco.com/t5/network-security/firepower-threat-defense-real-time-log-viewer/m-p/4945118#M1105257</link>
      <description>&lt;P&gt;You bumped an old topic.&lt;/P&gt;
&lt;P&gt;However since the creation of this topic, things has changed. In recent releases (7.0+ or 7.1+) Unified Events was introduced with the function "Live View" which essentially is a real-time logging (there is a minor delay, but its a few seconds in worst case)&lt;BR /&gt;This still requires logging at start of end of connection to be present and forwarded for the FMC events of course.&lt;/P&gt;</description>
      <pubDate>Fri, 20 Oct 2023 15:57:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-threat-defense-real-time-log-viewer/m-p/4945118#M1105257</guid>
      <dc:creator>AViftrup</dc:creator>
      <dc:date>2023-10-20T15:57:10Z</dc:date>
    </item>
    <item>
      <title>Re: Sorry but there's not</title>
      <link>https://community.cisco.com/t5/network-security/firepower-threat-defense-real-time-log-viewer/m-p/4945143#M1105261</link>
      <description>&lt;P&gt;I responded to a question from&amp;nbsp;&lt;SPAN class=""&gt;CiscoPurpleBelt&lt;/SPAN&gt;&amp;nbsp;&amp;nbsp;from earlier today.....&lt;/P&gt;&lt;P&gt;However since you brought it up, could you kindly point us in the right direction with some links?&lt;BR /&gt;&lt;BR /&gt;I found some links about the Live View.&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/secure-firewall/management-center/admin/710/management-center-admin-71/analysis-unified-events.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/secure-firewall/management-center/admin/710/management-center-admin-71/analysis-unified-events.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 20 Oct 2023 17:12:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-threat-defense-real-time-log-viewer/m-p/4945143#M1105261</guid>
      <dc:creator>James_1</dc:creator>
      <dc:date>2023-10-20T17:12:50Z</dc:date>
    </item>
  </channel>
</rss>

