cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
621
Views
0
Helpful
4
Replies

Unix Critical File Accessed Detected alert

sv7
Level 3
Level 3

We have observed more count for Unix Critical File Accessed Detected alert from the user “root” on the Host XYZ-FMC-SECONDARY. And also we observed multiple File names which is containing /etc, due to that alert is triggering. 

Can anyone help me how to resolve this.

4 Replies 4

Marvin Rhoads
Hall of Fame
Hall of Fame

What system is showing you this alert? Can you provide a sanitized screen shot?

Please check attach excel file.

Attaching a random spreadsheet does not answer the question "What system is showing you this alert?"

Its ALsec threat management tool that collects fmc logs 

Review Cisco Networking for a $25 gift card