cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2202
Views
0
Helpful
6
Replies

FMC Unified Events filtering

Jacob Gibb
Level 1
Level 1

Hello,

I am looking to understand where the filters ($(10.x.x.x) are created when filtering in the FMC unified events viewer similar to below. Some networks are there and some are not. In particular, I would like to filter on a subnet in general to view traffic from anyone in that subnet. Thanks. 

15155c26-e175-4026-bce3-ed833e8446e6.PNG 

1 Accepted Solution

Accepted Solutions

Marvin Rhoads
Hall of Fame
Hall of Fame

Just type in the address and subnet mask in CIDR format (a.b.c.d/xy - for example 192.168.1.0/24). The variable objects preceded by $ are created in the event that you have a network object already in existence for the subnet. They are not required to filter though.

View solution in original post

6 Replies 6

Eric R. Jones
Level 4
Level 4

So I watched the video on this, I need to go back and review it again;however, I do not remember the ability to filter or search for a particular IP address or anything else in this view. I felt that this, a failry ok replacement to the ASDM live view of traffic, wasn't what I want. Can you actually search for/filter for a particular IP or range of IP's?

 

thanks for the link. This actually helped me more than the video on the part I was curious about. 

Marvin Rhoads
Hall of Fame
Hall of Fame

Just type in the address and subnet mask in CIDR format (a.b.c.d/xy - for example 192.168.1.0/24). The variable objects preceded by $ are created in the event that you have a network object already in existence for the subnet. They are not required to filter though.

Thanks, Marvin. That did it!

ajmn
Cisco Employee
Cisco Employee
Review Cisco Networking for a $25 gift card