cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
842
Views
1
Helpful
6
Replies

Health monitoring graph FMC

FredrikW73
Level 1
Level 1

If I view the graphs for FMC in FMC GUI under System/Health Monitor/Monitor I see one diagram for Event rate. 

Example below: 

FredrikW73_0-1692885508582.png

What type of events is this, all event types? 

Also 5.00 million events per sec seems wrong. What is the timeframe? Should the M be substituted for K?

6 Replies 6

Marvin Rhoads
Hall of Fame
Hall of Fame

The events are all types - Connection, Intrusion, Security Intelligence, Malware etc.

The "M" on the scale is "Mega" = 100,000 multiplier for the ordinal number on the scale.

Strange, isn't mega equal to 1 million?

mega (M) = 10 to the power of 6 = 1000.000

giga (G) =  10 to the power of 9 = 1000.000.000

tera (T) =  10 to the power of 12 = 1000.000.000.000

Sorry - my mistake. You are connect - M is mega/million.

That graph you shared is indeed surprisingly high. The couple of production FMCs I just checked are running in the single digit k events/second.

rhingel
Cisco Employee
Cisco Employee

Depending on how your ACP Rules are configured, you might be recording events on the start and end of connection, which would account for more EPS. I suggest to review the policies in place.

You might also be logging a lot of blocks from the Internet originating from malicious actors, script kiddies, attempts at DDOS etc.. Check by disabling logging on the default block or whatever rule(s) you use to block incoming traffic.

FredrikW73
Level 1
Level 1

After checking the number of events over time I can say with confidence that the labeling on
the diagram vertical axis is incorrect. We have approx 5K - 10K events per second not 5M - 10M events per second.

It is a bug/visual glitch.

We run FTD 7.0.5, maybe this is fixed in 7.2

Review Cisco Networking for a $25 gift card