12-28-2023 07:44 AM
Hello,
I am looking to understand where the filters ($(10.x.x.x) are created when filtering in the FMC unified events viewer similar to below. Some networks are there and some are not. In particular, I would like to filter on a subnet in general to view traffic from anyone in that subnet. Thanks.
Solved! Go to Solution.
12-29-2023 04:46 AM - edited 12-29-2023 04:47 AM
Just type in the address and subnet mask in CIDR format (a.b.c.d/xy - for example 192.168.1.0/24). The variable objects preceded by $ are created in the event that you have a network object already in existence for the subnet. They are not required to filter though.
12-28-2023 12:09 PM
So I watched the video on this, I need to go back and review it again;however, I do not remember the ability to filter or search for a particular IP address or anything else in this view. I felt that this, a failry ok replacement to the ASDM live view of traffic, wasn't what I want. Can you actually search for/filter for a particular IP or range of IP's?
12-28-2023 04:29 PM
01-02-2024 01:31 PM
thanks for the link. This actually helped me more than the video on the part I was curious about.
12-29-2023 04:46 AM - edited 12-29-2023 04:47 AM
Just type in the address and subnet mask in CIDR format (a.b.c.d/xy - for example 192.168.1.0/24). The variable objects preceded by $ are created in the event that you have a network object already in existence for the subnet. They are not required to filter though.
01-02-2024 07:54 AM
Thanks, Marvin. That did it!
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide