07-26-2016 07:38 PM - edited 03-12-2019 06:05 AM
Hi,
I have a problem regarding on my sourcefire management and firewall 5500-x series.The dashboard of may sourcefire did not loading.
and i try to check the memory of firewall it says the free space is bigger than the total space of the firewall.
i hope you someone can help me with this.
07-26-2016 10:58 PM
Hi,
Did you check the timestamp window if it is correctly set ?
Also, check if logging is enabled on the policy and if you are getting connection events ?
Try rebooting the box once and see if it helps .
Thanks,
Ankita
07-27-2016 12:30 AM
Hi Ankita,
the timestamp window is correctly set and also i've already enabled the logging.
For this time, it is hard for me to reboot the appliance because it is running on my production.
Is there any way or tweak to solve this problem??
Thanks in advance...
Bernard
07-27-2016 02:30 AM
Hello,
Always try to keep the device in the latest code to avail all new features with the device.After the proper installation and having all the required license including Firesight host license you need to make sure that the traffic has been properly redirected to pass through the Firepower.If the Firepower is redirecting the traffic you can see the same by enabling the logging under the access control policy by Policies > Access Control > Rules > Logging > Logging at beginning of connection or Logging at end of connection . Once after enabling logging, save and reapply or redeploy the policy changes. Each device has its own database connection settings. So you can refer the following link and see how much of events can be logged in the device.
http://www.cisco.com/c/en/us/td/docs/security/firesight/541/user-guide/F...
If you can see the respective connection events under Analysis > Connection Events , the dashboard data also should populate . If you already enabled the above and still no events are coming up then please perform the following by the login to Firesight CLI by elevating to root user.
1) Verify the following service is running
pmtool status | grep SFTop10Cacher
2) Restart the service
pmtool restartbyid SFTop10Cacher
3) You should see the service as running with a different pid
pmtool status | grep SFTop10Cacher
Verify the dashboard after 30 minutes.
Rate and mark correct if the post helps you.
Regards
Jetsy
10-12-2016 09:32 PM
Hi Jetsy,
If im going to restart the SFTop10Cacher, is there any chances that the appliance will restart also?
Thank You an Best Regards,
Bernard
10-13-2016 10:02 PM
Hello Bernard,
If you restarting just a SFTop10Cacher process it wont restart the system.
As I mentioned in the previous post , If you can see the respective connection events under Analysis > Connection Events , the dashboard data also should populate . If you already enabled the above and still no events are coming up then please perform the following by the login to Firesight CLI by elevating to root user.
1) Verify the following service is running
pmtool status | grep SFTop10Cacher
2) Restart the service
pmtool restartbyid SFTop10Cacher
3) You should see the service as running with a different pid
pmtool status | grep SFTop10Cacher
Verify the dashboard after 30 minutes.
Rate and mark correct if the post helps you.
Regards
Jetsy
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide