#1 - You want to make sure that no legitemate traffic is being dropped by an Access Policy rule and or another NGFW feature (IPS, AMP, etc). For this, make sure that you are logging all of the events and then ensure that you are reviewing the logs
#2 - Make sure that FireSIGHT (FMC) was configured correctly to perform Network, Application, Hosts and Users discovery. The IPS recommendations will be based on that discovery so it very important for this to happen properly.
#3 - If you have or planning to have the configurations locked down to the App level then make sure that no "uknown" type Apps are showing in your event logs.
I hope this helps!
Thank you for rating helpful posts!
Thank you for rating helpful posts!