03-31-2023 05:49 AM
Hello Everyone
We are currently monitoring Firepower events in Splunk through the "Cisco Secure Firewall App for Splunk". Anyhow, we got the request to also monitor changes to Firepower rules and policies. Has anyone of you ever done this? Are these events even logged?
Thanks in advance for your advice.
04-14-2023 03:06 PM
04-17-2023 02:26 AM
Hi @mkoli .
If I understood your request correctly, what you are looking for is a feature called "Change reconciliation" in FMC.
You can read more about it in this configuration guide Firepower Management Center Configuration Guide - Change Reconciliation .
The idea is that you can monitor changes to your rules or configuration and configure the system to send an email containing a detailed report of the changes.
If you find my reply solved your question or issue, kindly click the 'Accept as Solution' button and vote it as helpful.
You can also learn more about Cisco Secure Firewall (formerly known as NGFW) through our live Ask the Experts (ATXs) session. Check out Cisco Network Security ATXs Resources [https://community.cisco.com/t5/security-knowledge-base/cisco-network-security-ask-the-experts-resources/ta-p/4416493] to view the latest schedule for upcoming sessions, as well as the useful references, e.g. online guides, FAQs.
04-17-2023 06:35 AM
The methods mentioned earlier send only a summary of config changes (via syslog or via email).
The ability to send detailed syslog messages regarding configuration changes is a feature currently under development. We hope to see it in FMC version 7.4 later this year.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide