cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
965
Views
0
Helpful
1
Replies

Firepower Intrusion Events

Community,

I recently implemented FTD's and had a question. I am not seeing any Intrusion Events or Attackers populating in the Intrustion Events or Geolocation tabs in my dashboard. Is this because I have not yet enabled the "inspection" option in any of my ACP rules? I am still working out which rules I should be enabling "Inspection" on. Any help you can provide is greatly appreciated. 

Thank you.  

1 Reply 1

balaji.bandi
Hall of Fame
Hall of Fame

yes until you configure you won't be able to see any events

 

here is the start guide : (advice to read the document, and understand before you implement in Live network) - start with Monitor mode.

 

 

https://www.cisco.com/c/en/us/td/docs/security/firepower/60/configuration/guide/fpmc-config-guide-v60/Getting_Started_with_Intrusion_Policies.html

 

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

Review Cisco Networking for a $25 gift card