Heads Up :
The post you are writing will appear in a public forum. Please ensure all content is appropriate for public consumption. Review the employee guidelines for the community here.
When using the’ Variable Sets’ it important to understand how SNORT rules works. Cisco Firepower is using SNORT, and got a huge amount of SNORT rules in its database. SNORT is in general a heavy process in Firepower Threat Defense, so if we can free...
It is however paussible to get a running-lina-config from CLI if running a Firepower appliance. But the Sourcefire appliance can be backed up from the FMC as Marvin mentioned.
Hi @InTheJuniverse,
This event is simply a client calling a DNS name from 8.8.8.8 (google DNS) that has a "bad reputation".You can trigger this event byg doing a nslookup at 8.8.8.8 on examplemalwaredomain.com. /Nikolaj