How to capture though? Are they displayed in connection events? Server certificate should have SAN/CN/OU in clear at TLS1.2, but not sure if FTD/FMC captures this by default. It may be a snort3 thing, I only have access to snort2 sensors at the moment