cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
573
Views
5
Helpful
4
Replies

FTD 4115 Reporting

D@1984
Level 1
Level 1

Is there a way to show which rule traffic hit when generate a report? What I'm after is to be able to filter logs based on a rule name/number.

 

 

Thanks 

4 Replies 4

balaji.bandi
Hall of Fame
Hall of Fame

check this below may help you :

 

https://www.cisco.com/c/en/us/support/docs/security/firepower-ngfw/212330-firepower-management-center-display-acc.html

 

Long back i made using output of  - > show access-control-config  ( daily basis and made report) (out of the box)

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

Marvin Rhoads
Hall of Fame
Hall of Fame

If you're using FMC, use Analysis > Connection Events > Table View of Connection events. Assuming you have your rules set to log to FMC, that view will include the rule that the connection event hit. (You will have to scroll right to see it.)

You can generate a report from that page and add/remove columns as desired to display only the data you want.

D@1984
Level 1
Level 1

thanks Marvin, the last 3 column are url category, url reputation and device. I cant see any name or rule ID.

D@1984 be sure to switch to the "Table View of Connection Events". Then use the horizontal scroll bar (or zoom out) to see all the columns.

Table View of Connection Events columnsTable View of Connection Events columns

Review Cisco Networking products for a $25 gift card