Hi,
One possible solution to the issue of delayed intrusion alerts in Firepower is to check the configuration of the intrusion policy and the event action rules. Make sure that the policy is set to generate alerts for the desired severity levels and that the event action rules are configured to send alerts to the appropriate destination, such as email or syslog.
Also, check the health of the Firepower system, including the CPU, memory, and disk usage, as well as the network connectivity.
You can always run a packet capture that will show you if the email is being sent out or not and isolate the issue.
If the issue persists, consider opening a support case with Cisco TAC for further investigation and troubleshooting.
-----------------------------------------
If you find my reply solved your question or issue, kindly click the 'Accept as Solution' button and vote it as helpful.
You can also learn more about Secure Firewall (formerly known as NGFW) through our live Ask the Experts (ATXs) session. Check out Cisco Network Security ATXs Resources [https://community.cisco.com/t5/security-knowledge-base/cisco-network-security-ask-the-experts-resources/ta-p/4416493] to view the latest schedule for upcoming sessions, as well as the useful references, e.g. online guides, FAQs.
-----------------------------------------
Regards,
Divya Jain