12-09-2025 01:37 AM - edited 12-09-2025 01:57 AM
Hello,
I am struggling to find how to view intrusion and security intelligence related events on cdFMC. It seems I can only view connection events.
Here is another screenshot from an on-prem FMC, where you can select all sort of events, including intrusion and security-related events.
Anyone know how do I view intrusion and security intelligence events in cdFMC or is that not possible?
Thanks
/Chess
Solved! Go to Solution.
12-09-2025 07:43 AM
When you purchase CDO/cdFMC (which is now presented in the Security Cloud Control UI framework), you have the option of device management only or device management with logging. You can also add logging later as an a la carte option.See Table 1 here:
Once you have the logging licensed, Cisco will store unified event for 90 days per licensed firewall.
When you have that, the Unified Events in cdFMC will indeed display SI and other such events:
12-09-2025 02:35 AM
Hi,
I'm assuming this is what you're looking for? https://www.cisco.com/c/en/us/td/docs/security/cdo/cloud-delivered-firewall-management-center-in-cdo/managing-firewall-threat-defense-services-with-cisco-defense-orchestrator/m_analysis_unified_events.html
Thanks,
Cristian.
12-09-2025 05:54 AM
Hi,
I cannot find the Unified Events page in the cdFMC. However, I read this in the link you you sent
"The Unified Events page uses the Cisco Security Analytics and Logging data store as its event data source. You must have a valid Cisco Security Analytics and Logging subscription plan to view firewall events on the Unified Events page."
So I guess this means that a separate license is needed to view security and intrusion events?
/Chess
12-09-2025 07:43 AM
When you purchase CDO/cdFMC (which is now presented in the Security Cloud Control UI framework), you have the option of device management only or device management with logging. You can also add logging later as an a la carte option.See Table 1 here:
Once you have the logging licensed, Cisco will store unified event for 90 days per licensed firewall.
When you have that, the Unified Events in cdFMC will indeed display SI and other such events:
12-09-2025 11:54 PM
Thanks for the clarification, Marvin.
12-10-2025 12:13 AM
I found out there's away to check for security intelligence events. If I go to events and filter for
FTD events=Security Intelligence, they will show up as normal connection events, but when I check the destination IP with virus total, it is classified as malware or malicious.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide