12-23-2015 05:38 AM - edited 03-12-2019 05:51 AM
Hello all,
On ASA 5508 with firepower, ASDM ASA firepower monitoring/real time eventing not showing any logs. Access control policy have logging enable
( Log at Beginning and End of Connection ) and send to Event viewer is checked. On dashboard i have reporting working well.
Can someone help me with this issue? I have provide screenshot below.
Regards
Petar
12-23-2015 10:38 AM
Hi,
On ASA , i hope the traffic is being redirected to the SFR , you can verify that by : show service-policy sfr and see the packets increasing.
Go on Access control policy and check if Logging is enabled on it and then also on right hand corner you have the window to increase the time frame , increase that for a week and see if you get any events out there.
If all of that is fine check on the sensor:
/var/sf/detection-engine , press tab and then go to instance
/var/sf/detection-engine/*/instance-1 ,Check for conn-unified bookmark file , see what date it was updated.
Also check the below on SFR :
pmtool status |grep SFData
SFdatacorrelator service should be running , otherwise you can try restarting it and see if that helps.
Regards,
Aastha Bhardwaj
Rate it that helps!!!
12-24-2015 01:34 AM
Hello Aastha,
Traffic is being redirected but when i checked with "show service-policy sfr", i noticed "SFR: card status Down, mode fail-open". I rebooted SFR but still, issue occured again "Card status down".
Also in ASA Firepower status "Data plane status" is down
Do You have idea how to bring it up?
Thank You kindly
Petar
12-24-2015 10:02 AM
Hi,
If you have reloaded the module and still the data plane status is down then we need to get that up first.
Try : sw-module module sfr reset and see if that helps.
Regards,
Aastha Bhardwaj
Rate if that helps!!!
12-24-2015 11:23 PM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide