cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1259
Views
0
Helpful
4
Replies

How to check Snort events/logs in FTD/FMC?

PacketSpartan
Level 1
Level 1

Hi All 

Is there a way to check the Snort events/logs on the SFR or on the FMC?

We need to rule out our Firepower module for a recent outage

Thank you in advance

CCNA R&S
4 Replies 4

This is not a valid link, it just takes me back to my own post 

 

Could you give me the link again please

CCNA R&S

sorry typo, I correct it

Marvin Rhoads
Hall of Fame
Hall of Fame

If you are using FMC and have enabled the policy rules to "send connection events to FMC", then you can check the Analysis > Connection Events or Security Intelligence Events views.

Note that connection events often fill up the allocated space in the database and older events age out - often in less than a day depending on your environment.

Using an external log server can alleviate this - the link shared by @MHM Cisco World provides more detail on that. (But obviously it won't help you for anything that's past already.)

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card