cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
122
Views
0
Helpful
1
Replies

No Malware events showing in FMC

This is a new FMC deployment and I have migrated several FTDs into it. I am not seeing any events in Malware which is a bit strange.. would expect to see something in here...

NetworkMonkey101_0-1737550613934.png

 

1 Reply 1

Marvin Rhoads
Hall of Fame
Hall of Fame

Have you created a File policy and associated it with rule(s) in your ACP along with a Malware license being assigned to the relevant FTD devices?

If so, also keep in mind that firewall Malware policy only applies to transfer of files it can actually see - i.e., things sent via http (not https which is 95-99% of web traffic) or something like unencrypted ftp. Do you see any file events indicating the device is doing a file lookup to check for malware? These are easily filterable in the Unified Events page.

Review Cisco Networking for a $25 gift card