09-23-2022 07:47 AM
Hello,
We have Cisco FTD and FMC, version is 7.0.1
I Would like to configure FTD in such way:
When Endpoint device will be compromised then FMC must notify to me by Email. Is it possible?
Solved! Go to Solution.
09-23-2022 10:04 AM - edited 09-23-2022 10:05 AM
As I understand need to create Correlation Policy.
As condition I use "IOC Tag", am I correct?
09-23-2022 10:04 AM - edited 09-23-2022 10:05 AM
As I understand need to create Correlation Policy.
As condition I use "IOC Tag", am I correct?
09-23-2022 10:08 AM
As a result, I received mail from FMC:
But is it possible to somehow edit mail body? Not very informative right now
09-26-2022 11:27 PM - edited 09-26-2022 11:28 PM
As I figured out configuration is a correct, FMC sends alert after device was compromised, but I can't change email body
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide