11-29-2018 08:38 AM - edited 02-21-2020 08:31 AM
I am slightly new to the FMC product and I have learned to do things like policies and device administration. Now I am looking at how to see what is going on. I created a policy on a new set of ASAs/SFRs that is in "monitor" mode because I want to see whats talking to what, How can I see a report on just these devices and whats going on?
11-29-2018 09:02 AM
Yea your only going to see traffic that your logging. One feature that may help you with reporting is when you navigate to Analysys\Search and your filtering on connection events. You can then click the link at the top right of the page that says "Report Designer", which will open a custom report based on the filters you have configured in your search. Hope this helps!
11-29-2018 11:27 AM - edited 11-29-2018 11:29 AM
So I cant see anything in monitor mode? Seems ironic no?
I also don't see any option of reports on the Analysis>Search area.
11-29-2018 11:39 AM
Actually monitor is an action type so believe it or not if its not set to log that acl rule under logging then I don't believe you'll see any events. Unless Cisco has updated something, but that's how my setup used to work.
After you navigate to Analysis>Search> you can select connection events in the drop down box and then hit the search button. Then once you see the connection events listed you can open the Report Designer.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide