cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
873
Views
0
Helpful
1
Replies

Firepower Intrusion Events

Community,

I recently implemented FTD's and had a question. I am not seeing any Intrusion Events or Attackers populating in the Intrustion Events or Geolocation tabs in my dashboard. Is this because I have not yet enabled the "inspection" option in any of my ACP rules? I am still working out which rules I should be enabling "Inspection" on. Any help you can provide is greatly appreciated. 

Thank you.  

1 Reply 1

balaji.bandi
VIP Community Legend VIP Community Legend
VIP Community Legend

yes until you configure you won't be able to see any events

 

here is the start guide : (advice to read the document, and understand before you implement in Live network) - start with Monitor mode.

 

 

https://www.cisco.com/c/en/us/td/docs/security/firepower/60/configuration/guide/fpmc-config-guide-v60/Getting_Started_with_Intrusion_Policies.html

 

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Recognize Your Peers