<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Events are pruning too quickly!! in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/events-are-pruning-too-quickly/m-p/2923302#M18474</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;I'm inside of the Firepower Management Center (in the connection summary, looking at my URL tab) just monitoring traffic, but I've noticed that events are pruning very quickly. What I mean is that it is categorizing Traffic by URL Category such as Music, Business and Economy, and even Adult and Pornography, but if I click on them to see who was looking at what, I get this message.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;H2&gt;Info&lt;/H2&gt;
&lt;P&gt;&lt;SPAN&gt;Event counts may differ from Dashboard as events are pruned.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;No Records&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Try adjusting the time window. Note that older records may have been pruned to conserve disk space.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;This is just for the previous hour. I've increased the database limit/event count to what I thought was the maximum based on some Googling I did, but I haven't had any luck monitoring this. What do you recommend I should try next?&lt;/P&gt;</description>
    <pubDate>Tue, 14 Jun 2016 13:42:25 GMT</pubDate>
    <dc:creator>confused_guy45</dc:creator>
    <dc:date>2016-06-14T13:42:25Z</dc:date>
    <item>
      <title>Events are pruning too quickly!!</title>
      <link>https://community.cisco.com/t5/network-security/events-are-pruning-too-quickly/m-p/2923302#M18474</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;I'm inside of the Firepower Management Center (in the connection summary, looking at my URL tab) just monitoring traffic, but I've noticed that events are pruning very quickly. What I mean is that it is categorizing Traffic by URL Category such as Music, Business and Economy, and even Adult and Pornography, but if I click on them to see who was looking at what, I get this message.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;H2&gt;Info&lt;/H2&gt;
&lt;P&gt;&lt;SPAN&gt;Event counts may differ from Dashboard as events are pruned.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;No Records&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Try adjusting the time window. Note that older records may have been pruned to conserve disk space.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;This is just for the previous hour. I've increased the database limit/event count to what I thought was the maximum based on some Googling I did, but I haven't had any luck monitoring this. What do you recommend I should try next?&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jun 2016 13:42:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/events-are-pruning-too-quickly/m-p/2923302#M18474</guid>
      <dc:creator>confused_guy45</dc:creator>
      <dc:date>2016-06-14T13:42:25Z</dc:date>
    </item>
    <item>
      <title>Hi It could just be that too</title>
      <link>https://community.cisco.com/t5/network-security/events-are-pruning-too-quickly/m-p/2923303#M18490</link>
      <description>&lt;P&gt;Hi It could just be that too many events are being generated which are making the database limit reach. What you can do is to reduce the no. of logging. &lt;/P&gt;
&lt;P&gt;Check each rule and make sure that logging is enabled only once either at beginning or end of connection but not both.&lt;/P&gt;
&lt;P&gt;If there are still too many connections, disable logging on default rule.&lt;/P&gt;
&lt;P&gt;Overall it would depend on which model of FMC you have and how many sensors are there.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Rate if helps.&lt;/P&gt;
&lt;P&gt;Yogesh&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jun 2016 13:50:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/events-are-pruning-too-quickly/m-p/2923303#M18490</guid>
      <dc:creator>yogdhanu</dc:creator>
      <dc:date>2016-06-14T13:50:35Z</dc:date>
    </item>
    <item>
      <title>Hi ,</title>
      <link>https://community.cisco.com/t5/network-security/events-are-pruning-too-quickly/m-p/2923304#M18509</link>
      <description>&lt;P&gt;Hi ,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Refer : http://www.cisco.com/c/en/us/support/docs/security/firesight-management-center/118012-troubleshoot-firesight-00.html&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Probably the amount of traffic that is being logged is causing the issue.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Aastha Bhardwaj&lt;/P&gt;
&lt;P&gt;Rate if that helps!!!&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jun 2016 16:37:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/events-are-pruning-too-quickly/m-p/2923304#M18509</guid>
      <dc:creator>Aastha Bhardwaj</dc:creator>
      <dc:date>2016-06-14T16:37:19Z</dc:date>
    </item>
    <item>
      <title>Hello Team,</title>
      <link>https://community.cisco.com/t5/network-security/events-are-pruning-too-quickly/m-p/2923305#M18522</link>
      <description>&lt;P&gt;Hello Team,&lt;/P&gt;
&lt;P&gt;What is the Firesight model that you have ?&lt;/P&gt;
&lt;P&gt;Based on the fIresight model there is a minimum and maximum database limit that can be used.&lt;/P&gt;
&lt;P&gt;Database limit can be set under system policy settings. Please verify what is your connection events database limit under system policy.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also let us know the model of the Firesight. Based on the models the limits varies.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Rate if this answer helps you.&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Jetsy&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jun 2016 05:45:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/events-are-pruning-too-quickly/m-p/2923305#M18522</guid>
      <dc:creator>Jetsy Mathew</dc:creator>
      <dc:date>2016-06-15T05:45:31Z</dc:date>
    </item>
    <item>
      <title>Thank you. I believe I'm at</title>
      <link>https://community.cisco.com/t5/network-security/events-are-pruning-too-quickly/m-p/2923306#M18533</link>
      <description>&lt;P&gt;Thank you. I believe I'm at the maximum limit for my model, so it seems strange!&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jun 2016 21:15:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/events-are-pruning-too-quickly/m-p/2923306#M18533</guid>
      <dc:creator>confused_guy45</dc:creator>
      <dc:date>2016-06-15T21:15:15Z</dc:date>
    </item>
    <item>
      <title>Very common issue in this</title>
      <link>https://community.cisco.com/t5/network-security/events-are-pruning-too-quickly/m-p/2923307#M18546</link>
      <description>&lt;P&gt;Very common issue in this product in my opinion. Far too easy to exceed.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;After about a week in production you need to spend time trimming out logging of high hitting flows.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The overview page can quickly show you the top hitters. Case by case basis really.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Do you really need all the flows of traffic like kerberos, ldap, dns (maybe), reply connections to http (yes a separate flow for the reply from an outbound http connection = exhaustion quickly).&lt;/P&gt;
&lt;P&gt;So a search in Event Connections with source port of 80 or 443 and destination of your internal network.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 04 Aug 2016 02:24:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/events-are-pruning-too-quickly/m-p/2923307#M18546</guid>
      <dc:creator>evan.chadwick1</dc:creator>
      <dc:date>2016-08-04T02:24:36Z</dc:date>
    </item>
  </channel>
</rss>

