<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hi, in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/connection-events-and-storage-size/m-p/3006518#M43083</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Is it possible in database to delete Malware Event Database (currently configured 1million events)?, we havent malware connections enabled. And this million of event is added to "connection database"????&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;This would do that we have more size for our connections?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;thanks&lt;/P&gt;</description>
    <pubDate>Tue, 07 Mar 2017 15:37:14 GMT</pubDate>
    <dc:creator>SupportAC</dc:creator>
    <dc:date>2017-03-07T15:37:14Z</dc:date>
    <item>
      <title>Connection events and storage size</title>
      <link>https://community.cisco.com/t5/network-security/connection-events-and-storage-size/m-p/3006514#M43079</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;We have configured 2 Firepower 8350 (v5.4.0.7) with the same health policy, system policy, etc. In one of these if we go to "Connections events" we can se the events recevided, but not in the another one (its empty)&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;On the another hand, we would like to increase the database size for logs in Virtual defense center, where can increase the events stored in firepower too?? /var/log is empty but it seems like FPower can assume more events.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 13:47:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/connection-events-and-storage-size/m-p/3006514#M43079</guid>
      <dc:creator>SupportAC</dc:creator>
      <dc:date>2019-03-10T13:47:22Z</dc:date>
    </item>
    <item>
      <title>@Soporte Acuntia  ,</title>
      <link>https://community.cisco.com/t5/network-security/connection-events-and-storage-size/m-p/3006515#M43080</link>
      <description>&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://supportforums.cisco.com/users/soporteAC"&gt;soporteAC&lt;/A&gt;&lt;/SPAN&gt;&amp;nbsp; ,&lt;/P&gt;
&lt;P&gt;A virtual FMC is limited by design to 10 million events total. See Table 3 of the product data sheet for confirmation:&lt;/P&gt;
&lt;P&gt;http://www.cisco.com/c/en/us/products/collateral/security/firesight-management-center/datasheet-c78-736775.html&lt;/P&gt;
&lt;P&gt;That includes 2 million Connection Events and 1 million each of various other types of events as shown in your FMC under System &amp;gt; Configuration &amp;gt; Database. You can change the relative allocations and even go so far as to allocate all 10 milion records to connections events. But the overall database size is not configurable nor is the amount of disk allocated to the VM.&lt;/P&gt;
&lt;P&gt;See the following section of the Configuration Guide for further guidance:&lt;/P&gt;
&lt;P&gt;http://www.cisco.com/c/en/us/td/docs/security/firepower/620/configuration/guide/fpmc-config-guide-v62/system_configuration.html#concept_C94E9492C76E4CCC9100B3139C7CF771&lt;/P&gt;</description>
      <pubDate>Sat, 04 Mar 2017 01:58:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/connection-events-and-storage-size/m-p/3006515#M43080</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2017-03-04T01:58:34Z</dc:date>
    </item>
    <item>
      <title>Hi, thanks a lot for your</title>
      <link>https://community.cisco.com/t5/network-security/connection-events-and-storage-size/m-p/3006516#M43081</link>
      <description>&lt;P&gt;Hi, thanks a lot for your response.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;What impact would have to increase database connections events in FMC???? any recommended value???&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;going into firepower by ssh and running df -h we see a lot of free space in /var/log. So we have space to store more logs.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;regards&lt;/P&gt;</description>
      <pubDate>Tue, 07 Mar 2017 08:23:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/connection-events-and-storage-size/m-p/3006516#M43081</guid>
      <dc:creator>SupportAC</dc:creator>
      <dc:date>2017-03-07T08:23:22Z</dc:date>
    </item>
    <item>
      <title>The sum total of all event</title>
      <link>https://community.cisco.com/t5/network-security/connection-events-and-storage-size/m-p/3006517#M43082</link>
      <description>&lt;P&gt;The sum total of all event types cannot exceed the 10 million hard limit. It does not matter that there is storage - the database size is limited and Cisco has no current plans to change that limit on the VM platform.&lt;/P&gt;
&lt;P&gt;They feel the negative impacts to the customer experience outweigh the benefits for those customers with smaller deployments (such as the virtual FMC is designed for) looking to scale up to mid-size. For larger databases they really strongly recommend buying a hardware-based FMC appliance.&lt;/P&gt;
&lt;P&gt;You can reallocate within the categories so as to adjust their respective maxumium records according to your unique operational environemnt and needs - as long as the total is 10 million or less.&lt;/P&gt;</description>
      <pubDate>Tue, 07 Mar 2017 10:03:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/connection-events-and-storage-size/m-p/3006517#M43082</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2017-03-07T10:03:00Z</dc:date>
    </item>
    <item>
      <title>Hi,</title>
      <link>https://community.cisco.com/t5/network-security/connection-events-and-storage-size/m-p/3006518#M43083</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Is it possible in database to delete Malware Event Database (currently configured 1million events)?, we havent malware connections enabled. And this million of event is added to "connection database"????&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;This would do that we have more size for our connections?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;thanks&lt;/P&gt;</description>
      <pubDate>Tue, 07 Mar 2017 15:37:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/connection-events-and-storage-size/m-p/3006518#M43083</guid>
      <dc:creator>SupportAC</dc:creator>
      <dc:date>2017-03-07T15:37:14Z</dc:date>
    </item>
    <item>
      <title>Think of it as one big</title>
      <link>https://community.cisco.com/t5/network-security/connection-events-and-storage-size/m-p/3006519#M43084</link>
      <description>&lt;P&gt;Think of it as one big database with multiple tables. Total limit is 10 million records.&lt;/P&gt;
&lt;P&gt;You can set the Malware Event Database records to zero and then allocate those 1 million records to the Connection Event Database.&lt;/P&gt;</description>
      <pubDate>Tue, 07 Mar 2017 22:28:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/connection-events-and-storage-size/m-p/3006519#M43084</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2017-03-07T22:28:55Z</dc:date>
    </item>
    <item>
      <title>Marvin, </title>
      <link>https://community.cisco.com/t5/network-security/connection-events-and-storage-size/m-p/3006520#M43085</link>
      <description>&lt;P&gt;Marvin,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I found this document, who stats a 49 million events for FMC on virtual platform.&lt;/P&gt;
&lt;P&gt;http://www.cisco.com/c/en/us/td/docs/security/firepower/60/configuration/guide/fpmc-config-guide-v60/Management_Center_System_Configuration.html#concept_C94E9492C76E4CCC9100B3139C7CF771&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;TABLE cellpadding="3" cellspacing="0" width="90%" bordercolor="#808080" summary="" frame="border" border="1" rules="all"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD class="cellrowborder" valign="top" width="33.33333333333333%" headers="d233221e2557 "&gt;
&lt;P&gt;Connection events&lt;/P&gt;
&lt;P&gt;&lt;A name="ID-2258-0000026d__ID-2258-000002ad"&gt;&lt;/A&gt;Security Intelligence events&lt;/P&gt;
&lt;/TD&gt;
&lt;TD class="cellrowborder" valign="top" width="44.44444444444444%" headers="d233221e2562 "&gt;
&lt;P&gt;&lt;A name="ID-2258-0000026d__ID-2258-000002af"&gt;&lt;/A&gt;49 million (&lt;SPAN&gt;Management Center&lt;/SPAN&gt; Virtual) &lt;/P&gt;
&lt;P&gt;50 million (MC750) &lt;/P&gt;
&lt;P&gt;100 million (MC1500) &lt;/P&gt;
&lt;P&gt;300 million (MC2000)&lt;/P&gt;
&lt;P&gt;500 million (MC3500)&lt;/P&gt;
&lt;P&gt; 1 billion (MC4000)&lt;/P&gt;
&lt;P&gt;&lt;A name="ID-2258-0000026d__ID-2258-000002b5"&gt;&lt;/A&gt;Limit is shared between connection events and Security Intelligence events. The sum of the configured maximums cannot exceed this limit.&lt;/P&gt;
&lt;/TD&gt;
&lt;TD class="cellrowborder" valign="top" width="22.22222222222222%" headers="d233221e2567 "&gt;
&lt;P&gt;&lt;A name="ID-2258-0000026d__ID-2258-000002b7"&gt;&lt;/A&gt;Zero (disables storage)&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I see on configuration guide for 5.4 version, the limit was 10 millions, but apper as 6.0 version Cisco have "upgraded" it to 49 million.&lt;/P&gt;
&lt;P&gt;Currently we have a case on TAC to confirm this number.&lt;/P&gt;</description>
      <pubDate>Thu, 23 Mar 2017 16:26:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/connection-events-and-storage-size/m-p/3006520#M43085</guid>
      <dc:creator>samuelgerevini</dc:creator>
      <dc:date>2017-03-23T16:26:01Z</dc:date>
    </item>
    <item>
      <title>I strongly suspect a</title>
      <link>https://community.cisco.com/t5/network-security/connection-events-and-storage-size/m-p/3006521#M43086</link>
      <description>&lt;P&gt;I strongly suspect a documentation error there.&lt;/P&gt;
&lt;P&gt;I specifically brought up this 10 million event limitation with several Cisco Technical Marketing Engineers (TMEs) at Cisco Live Melbourne this month and they all confirmed the 10 million events limit and stated there were no near term plans to change that.&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I submitted a document feedback form to get confirmation. Please let us know what your TAC engineer says as well.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 24 Mar 2017 02:38:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/connection-events-and-storage-size/m-p/3006521#M43086</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2017-03-24T02:38:12Z</dc:date>
    </item>
    <item>
      <title>Have the limits been</title>
      <link>https://community.cisco.com/t5/network-security/connection-events-and-storage-size/m-p/3006522#M43087</link>
      <description>&lt;P&gt;Have the limits been increased &amp;nbsp;in the last 6 months?&lt;/P&gt;
&lt;P&gt;I dont' recall 1 billion before for FMC 4000&lt;/P&gt;
&lt;TABLE cellpadding="3" cellspacing="0" width="90%" bordercolor="#808080" summary="" frame="border" border="1" rules="all"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD class="cellrowborder" valign="top" width="NaN%" headers="d808852e24 "&gt;
&lt;P&gt;connection events&lt;/P&gt;
&lt;P&gt;&lt;A name="ID-2258-0000026d__ID-2258-000002ad"&gt;&lt;/A&gt;Security Intelligence Events&lt;/P&gt;
&lt;/TD&gt;
&lt;TD class="cellrowborder" valign="top" width="NaN%" headers="d808852e29 "&gt;
&lt;P&gt;&lt;A name="ID-2258-0000026d__ID-2258-000002af"&gt;&lt;/A&gt;10 million (&lt;SPAN&gt;Management Center&lt;/SPAN&gt; Virtual) &lt;/P&gt;
&lt;P&gt;50 million (MC750) &lt;/P&gt;
&lt;P&gt;100 million (MC1500) &lt;/P&gt;
&lt;P&gt;300 million (MC2000)&lt;/P&gt;
&lt;P&gt;500 million (MC3500)&lt;/P&gt;
&lt;P&gt; 1 billion (MC4000)&lt;/P&gt;
&lt;P&gt;&lt;A name="ID-2258-0000026d__ID-2258-000002b5"&gt;&lt;/A&gt;Upper event limit is shared between connection events and Security Intelligence events; the sum of configured maximums for the two events cannot exceed the upper event limit.&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;</description>
      <pubDate>Thu, 13 Apr 2017 02:21:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/connection-events-and-storage-size/m-p/3006522#M43087</guid>
      <dc:creator>evan.chadwick1</dc:creator>
      <dc:date>2017-04-13T02:21:08Z</dc:date>
    </item>
    <item>
      <title>The data sheet for FirePOWER</title>
      <link>https://community.cisco.com/t5/network-security/connection-events-and-storage-size/m-p/3006523#M43088</link>
      <description>&lt;P&gt;The data sheet for FirePOWER Management Center is still listing 300 million for the FMC 4000 (and even the new FMC 4500).&lt;/P&gt;
&lt;P&gt;See Table 3 here:&lt;/P&gt;
&lt;P&gt;http://www.cisco.com/c/en/us/products/collateral/security/firesight-management-center/datasheet-c78-736775.html&lt;/P&gt;</description>
      <pubDate>Fri, 14 Apr 2017 07:30:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/connection-events-and-storage-size/m-p/3006523#M43088</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2017-04-14T07:30:22Z</dc:date>
    </item>
    <item>
      <title>Re: I strongly suspect a</title>
      <link>https://community.cisco.com/t5/network-security/connection-events-and-storage-size/m-p/3219327#M43089</link>
      <description>&lt;P&gt;The actual database limit for the virtual FMC is 50 million events, combined for connection events and security intelligence events.&amp;nbsp; The default size for security intelligence is 1,000,000, which is why the documentation said 49,000,000.&amp;nbsp; However, if you were to reduce the number of SI events, you could add the same to connection events.&amp;nbsp; For example, you could have 500,000 SI events, and 49,500,000 connection events if you wanted.&lt;/P&gt;</description>
      <pubDate>Mon, 20 Nov 2017 08:28:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/connection-events-and-storage-size/m-p/3219327#M43089</guid>
      <dc:creator>ghalleen</dc:creator>
      <dc:date>2017-11-20T08:28:16Z</dc:date>
    </item>
    <item>
      <title>Re: I strongly suspect a</title>
      <link>https://community.cisco.com/t5/network-security/connection-events-and-storage-size/m-p/3229375#M43090</link>
      <description>&lt;P&gt;Any help in trimming?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Don't mean to hijack the thread, but we have been running several thousand users through a pair of ASA5555's and everything is zippy and working.. but reports are only showing about 12 hours in the past!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I contacted TAC and they immediately did what you guys are talking about.. upped the Connection Events table to 49,000,000. We got another couple of hours of reporting added to our 12 hours.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is it really ~$15,000 for a device that can give us a week's worth of URL filtering reports (IPS is licensed, but we have 6 rules in our Access Control Policy and not using IPS yet.. just a couple of different AD groups to filter URL's, nothing fancy)?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I only have logging on two of the rules in our ACP.. is there nothing I can do to trim that down?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Definitely a difficult product to wrap your head around, but once you get going, it seems to be working well.. but if I can't get more than ~16 hours of who went to what URL, this customer is going to have a fit that they have to buy another piece of equipment.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;FMC is currently a KVM virtual (6.2.0.2)... Thanks for all of this info! I was reading 10 million as well.. and thinking that TAC was upping it to 49 million without really knowing what was going on &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 08 Dec 2017 19:11:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/connection-events-and-storage-size/m-p/3229375#M43090</guid>
      <dc:creator>bkastor</dc:creator>
      <dc:date>2017-12-08T19:11:03Z</dc:date>
    </item>
    <item>
      <title>Re: I strongly suspect a</title>
      <link>https://community.cisco.com/t5/network-security/connection-events-and-storage-size/m-p/3332159#M43091</link>
      <description>&lt;P&gt;I am in the same exact position. We purchased a Virtual FMC which has three 5515-x ASA's feeding it and our total user count is roughly 5,000.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We currently cannot go back more then 3-4 hours of connection events. I opened a TAC case today and we played with all of the database settings, Cisco's answer was ultimately that we are putting to much traffic through it.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You are correct in that I am struggling to see the value in this.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;On top of that, the SI feeds seems to be unreliable. We received malware alerts for users that were updating their endpoint protection from Sophos. The link was one of Sopho's well known update URI's.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We tried white listing our DNS traffic and another one of our application update server's to trim down some of the logging but they still show up everywhere. In reports, in connection events etc.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 16 Feb 2018 01:33:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/connection-events-and-storage-size/m-p/3332159#M43091</guid>
      <dc:creator>JG1978</dc:creator>
      <dc:date>2018-02-16T01:33:00Z</dc:date>
    </item>
    <item>
      <title>Re: I strongly suspect a</title>
      <link>https://community.cisco.com/t5/network-security/connection-events-and-storage-size/m-p/3332180#M43092</link>
      <description>&lt;P&gt;It's a bit of a challenge to tune the logging on FMC.&amp;nbsp; Let me give you my thoughts on best practices.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;First of all, take a look at what all you're logging.&amp;nbsp; Almost certainly, you're logging connections you don't need.&amp;nbsp; For all of the generic network traffic (NTP, DHCP, and such), you should probably turn OFF logging to FMC.&amp;nbsp; If you want to keep all of it, send those logs to SYSLOG instead of FMC.&amp;nbsp; These types of communications are very chatty, and it's unlikely you're getting valuable information from them, but they are filling up your available log space in the database.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Another thing to look at is WHEN you're logging.&amp;nbsp; Are you logging at both Beginning and End of connection?&amp;nbsp; On each line in your Access Control Policy, think about whether you need both.&amp;nbsp; If you can get by with logging only at the end of connection, you'll save a lot of space in the database.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you have your SMTP inbound traffic going through the firewall -- especially if you have an email security appliance that it's destined to -- you likely don't need to log this traffic on the FMC.&amp;nbsp; You'll still get summary information, even if the individual logs are disabled.&amp;nbsp; Again, consider sending these logs only to your SYSLOG server (if you have one).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This process will be useful, as you look through your ACP.&amp;nbsp; In general, if you want the logs for historical reasons, send them to SYSLOG.&amp;nbsp; If they have a security reason, then keep them on the FMC.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I hope this helps.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Gary&lt;/P&gt;</description>
      <pubDate>Fri, 16 Feb 2018 04:00:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/connection-events-and-storage-size/m-p/3332180#M43092</guid>
      <dc:creator>ghalleen</dc:creator>
      <dc:date>2018-02-16T04:00:10Z</dc:date>
    </item>
    <item>
      <title>Re: I strongly suspect a</title>
      <link>https://community.cisco.com/t5/network-security/connection-events-and-storage-size/m-p/3332510#M43094</link>
      <description>Thanks, those are some good suggestions and I am working towards trimming down as much as possible.</description>
      <pubDate>Fri, 16 Feb 2018 14:54:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/connection-events-and-storage-size/m-p/3332510#M43094</guid>
      <dc:creator>JG1978</dc:creator>
      <dc:date>2018-02-16T14:54:14Z</dc:date>
    </item>
    <item>
      <title>Re: @Soporte Acuntia  ,</title>
      <link>https://community.cisco.com/t5/network-security/connection-events-and-storage-size/m-p/3803801#M43095</link>
      <description>&lt;P&gt;Dear,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;how to remove all previous connection events for reducing database size.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 18 Feb 2019 05:29:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/connection-events-and-storage-size/m-p/3803801#M43095</guid>
      <dc:creator>Syed Nabeel Ahmad</dc:creator>
      <dc:date>2019-02-18T05:29:02Z</dc:date>
    </item>
    <item>
      <title>Re: The sum total of all event</title>
      <link>https://community.cisco.com/t5/network-security/connection-events-and-storage-size/m-p/4986423#M1107345</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/280298"&gt;@Wonxie&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Note the FMCv300 with a capacity of 60 million events was since released.&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;See Table 3 here: &lt;A href="https://www.cisco.com/c/en/us/products/collateral/security/firesight-management-center/datasheet-c78-736775.html#Platformspecifications" target="_blank"&gt;https://www.cisco.com/c/en/us/products/collateral/security/firesight-management-center/datasheet-c78-736775.html#Platformspecifications&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 28 Dec 2023 12:36:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/connection-events-and-storage-size/m-p/4986423#M1107345</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2023-12-28T12:36:17Z</dc:date>
    </item>
    <item>
      <title>Re: @Soporte Acuntia  ,</title>
      <link>https://community.cisco.com/t5/network-security/connection-events-and-storage-size/m-p/5144022#M1114237</link>
      <description>&lt;P&gt;Hi Marvin ,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;to increase the logging as per the guide can be done&amp;nbsp;&amp;nbsp;&lt;SPAN class="ph"&gt;&lt;SPAN class="ph menucascade"&gt;&lt;STRONG&gt;&lt;SPAN class="ph uicontrol"&gt;System&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&amp;gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;SPAN class="ph uicontrol"&gt;&lt;STRONG&gt;Configuration&amp;nbsp;&lt;/STRONG&gt; then &lt;STRONG&gt;Database&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="ph"&gt;&lt;SPAN class="ph menucascade"&gt;&lt;SPAN class="ph uicontrol"&gt;&lt;STRONG&gt;But that option is not Exist on (CDO ) Cloud Delivery Orchestrator.&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="ph"&gt;&lt;SPAN class="ph menucascade"&gt;&lt;SPAN class="ph uicontrol"&gt;&lt;STRONG&gt;any help&amp;nbsp;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Jul 2024 08:23:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/connection-events-and-storage-size/m-p/5144022#M1114237</guid>
      <dc:creator>Ahmed Muneer</dc:creator>
      <dc:date>2024-07-12T08:23:42Z</dc:date>
    </item>
    <item>
      <title>Re: @Soporte Acuntia  ,</title>
      <link>https://community.cisco.com/t5/network-security/connection-events-and-storage-size/m-p/5144250#M1114248</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/577866"&gt;@Ahmed Muneer&lt;/a&gt; Logging is a separate subscription in CDO (Cisco Defense Orchestrator). It's known there as Secure Analytics and Logging (SAL) and is available in several tiers and options - all of which require an additional license.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.defenseorchestrator.com/#!r-about-secure-logging-analytics-saas.html?highlight=security%20analytics%20and%20logging" target="_blank" rel="noopener"&gt;https://docs.defenseorchestrator.com/#!r-about-secure-logging-analytics-saas.html?highlight=security%20analytics%20and%20logging&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;If you don't have it licensed, then CDO won't show you connection or event logs. You do have the option of setting up an on-prem FMC (or SNA data store) just for logging while continuing to use the cdFMC in CDO for management.&lt;/P&gt;</description>
      <pubDate>Fri, 12 Jul 2024 13:35:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/connection-events-and-storage-size/m-p/5144250#M1114248</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2024-07-12T13:35:34Z</dc:date>
    </item>
  </channel>
</rss>

