cancel
Showing results forĀ 
Search instead forĀ 
Did you mean:Ā 
cancel
612
Views
0
Helpful
4
Replies

Unix Critical File Accessed Detected alert

sv7
Level 3
Level 3

We have observed more count for Unix Critical File Accessed Detected alert from the user ā€œrootā€ on the Host XYZ-FMC-SECONDARY. And also we observed multiple File names which is containing /etc, due to that alert is triggering. 

Can anyone help me how to resolve this.

4 Replies 4

Marvin Rhoads
Hall of Fame
Hall of Fame

What system is showing you this alert? Can you provide a sanitized screen shot?

Please check attach excel file.

Attaching a random spreadsheet does not answer the question "What system is showing you this alert?"

Its ALsec threat management tool that collects fmc logs 

Review Cisco Networking for a $25 gift card