Hello, I can not find an answer to this anywhere online. It would seem self-explanatory, but apparently it's not. What encompasses the "Snort - Denied Flows" that can be seen for the FTD in FMC's Health Monitor? The numbers I am seeing in the "Snort - Denied Flow" section do not match the number of IPS/SI blocks logged. In fact, the are no IPS rule or SI blocks happening (and I am somewhat certain of this because I log them all) but the Snort - Denied Flow stats go up and down all day. What other events contribute to Snort denied flows that would be show on this graph? Any insight is appreciated. Thanks!
