I recently started updating my ACL rules on my FTD devices in FMC from using ports to using application filters. The problem I've been running up against is trying to use packet tracer to identify what rule will get hit in a given scenario. It seems like packet tracer shows the first rule that matches the correct zone and IP address. It shows the traffic allowed pending AppID. Even though the AppID in the rule doesn't match the port I'm using in packet tracer. This is especially frustrating when I'm asked to add a new rule and I have to sort through 100 ACLs that are all referencing objects. I can't quickly determine if there is a rule that already accommodates the access needed.
The easiest way I've found to do this at the moment is to either packet capture, or use the event viewer(Assuming it hits a rule that is logging). Is Packet Tracer now completely useless with APPIDs? Or is there a better way to do this?