- Getting Started With Firepower
-
- An Overview of Intrusion Detection and Prevention
- Layers in Intrusion and Network Analysis Policies
- Getting Started with Intrusion Policies
- Tuning Intrusion Policies Using Rules
- Tailoring Intrusion Protection to Your Network Assets
- Sensitive Data Detection
- Globally Limiting Intrusion Event Logging
- The Intrusion Rules Editor
- Intrusion Prevention Performance Tuning
- Security, Internet Access, and Communication Ports
- Command Line Reference
Correlation and Compliance Events
The following topics describe how to view correlation and compliance events.
Viewing Correlation Events
|
Smart License |
Classic License |
Supported Devices |
Supported Domains |
Access |
|---|---|---|---|---|
|
Any |
Any |
Any |
Any |
Admin/Any Security Analyst |
When a correlation rule within an active correlation policy triggers, the system generates a correlation event and logs it to the database.
![]() Note | When a compliance white list within an active correlation policy triggers, the system generates a white list event. |
You can view a table of correlation events, then manipulate the event view depending on the information you are looking for.
In a multidomain deployment, you can view data for the current domain and for any descendant domains. You cannot view data from higher level or sibling domains.
The page you see when you access correlation events differs depending on the workflow you use. You can use the predefined workflow, which includes the table view of correlation events. You can also create a custom workflow that displays only the information that matches your specific needs.
| Step 1 | Choose
.
Optionally, to use a different workflow, including a custom workflow, click (switch workflow) by the workflow title.
| ||
| Step 2 | Optionally, adjust the time range as described in Changing the Time Window. | ||
| Step 3 | Perform any of the following actions:
|
Correlation Event Fields
When a correlation rule triggers, the system generates a correlation event. The fields in the correlation events table that can be viewed and searched are described in the following table.
Using Compliance White List Workflows
|
Smart License |
Classic License |
Supported Devices |
Supported Domains |
Access |
|---|---|---|---|---|
|
Any |
Any |
Any |
Any |
Admin/Any Security Analyst/Discovery Admin |
The Firepower Management Center provides a set of workflows that you can use to analyze the white list events and violations that are generated for your network. The workflows are, along with the network map and dashboard, a key source of information about the compliance of your network assets.
The system provides predefined workflows for white list events and violations. You can also create custom workflows. When you are using a compliance white list workflow, you can perform many common actions.
| Step 1 | Access a white list workflow using the menu. |
| Step 2 | You have the following options:
|
Viewing White List Events
|
Smart License |
Classic License |
Supported Devices |
Supported Domains |
Access |
|---|---|---|---|---|
|
Any |
Any |
Any |
Any |
Admin/Any Security Analyst/Discovery Admin |
After its initial evaluation, the system generates a white list event whenever a monitored host goes out of compliance with an active white list. White list events are a special kind of correlation event, and are logged to the Management Center correlation event database.
You can use the Firepower Management Center to view a table of compliance white list events. Then, you can manipulate the event view depending on the information you are looking for.
In a multidomain deployment, you can view data for the current domain and for any descendant domains. You cannot view data from higher level or sibling domains.
The page you see when you access white list events differs depending on the workflow you use. You can use a predefined workflow, which terminates in a table view of events. You can also create a custom workflow that displays only the information that matches your specific needs.
| Step 1 | Choose . |
| Step 2 | You have the following options:
|
White List Event Fields
White list events, which you can view and search using workflows, contain the following fields.
Device
The name of the managed device that detected the white list violation.
Description
A description of how the white list was violated. For example:
Client “AOL Instant Messenger” is not allowed.Violations that involve an application protocol indicate the application protocol name and version, as well as the port and protocol (TCP or UDP) it is using. If you restrict prohibitions to a particular operating system, the description includes the operating system name. For example:
Server "ssh / 22 TCP (OpenSSH 3.6.1p2)" is not allowed on Operating System “Linux Linux 2.4 or 2.6”.Domain
The domain of the host that has become non-compliant with the white list. This field is only present if you have ever configured the Firepower Management Center for multitenancy.
Host Criticality
The user-assigned host criticality of the source host that is out of compliance with the white list: None, Low, Medium, or High.
IP Address
The IP address of the host that has become non-compliant with the white list.
Policy
The name of the correlation policy that was violated, that is, the correlation policy that includes the white list.
Port
The port, if any, associated with the discovery event that triggered an application protocol white list violation (a violation that occurred as a result of a non-compliant application protocol). For other types of white list violations, this field is blank.
Priority
The priority specified by the policy or white list that triggered the policy violation. This is determined either by the priority of the white list in a correlation policy or by the priority of the correlation policy itself. Note that the white list priority overrides the priority of its policy. When searching this field, enter none for no priority.
Time
The date and time that the white list event was generated. This field is not searchable.
User
The identity of any known user logged in to the host that has become non-compliant with the white list.
White List
Count
The number of events that match the information that appears in each row. Note that the Count field appears only after you apply a constraint that creates two or more identical rows. This field is not searchable.
Viewing White List Violations
|
Smart License |
Classic License |
Supported Devices |
Supported Domains |
Access |
|---|---|---|---|---|
|
Any |
Any |
Any |
Any |
Admin/Any Security Analyst/Discovery Admin |
The system keeps a record of the current white list violations on your network. Each violation represents something disallowed running on one of your hosts. If a host becomes compliant, the system removes the now-corrected violation from the database.
You can use the Firepower Management Center to view a table of white list violations for all active white lists. Then, you can manipulate the event view depending on the information you are looking for.
The page you see when you access white list violations differs depending on the workflow you use. The predefined workflows terminate in a host view, which contains a host profile for every host that meets your constraints. You can also create a custom workflow that displays only the information that matches your specific needs.
In a multidomain deployment, you can view data for the current domain and for any descendant domains. You cannot view data from higher level or sibling domains.
| Step 1 | Choose . |
| Step 2 | You have the following options:
|
White List Violation Fields
White list violations, which you can view and search using workflows, contain the following fields.
Domain
The domain where the non-compliant host resides. This field is only present if you have ever configured the Firepower Management Center for multitenancy.
Information
Any available vendor, product, or version information associated with the white list violation. For protocols that violate a white list, this field also indicates whether the violation is due to a network or transport protocol.
IP Address
Port
The port, if any, associated with the event that triggered an application protocol white list violation (a violation that occurred as a result of a non-compliant application protocol). For other types of white list violations, this field is blank.
Protocol
The protocol, if any, associated with the event that triggered an application protocol white list violation (a violation that occurred as a result of a non-compliant application protocol). For other types of white list violations, this field is blank.
Time
The date and time that the white list violation was detected.
Type
The type of white list violation, that is, whether the violation occurred as a result of a non-compliant:
White List
Count
The number of events that match the information that appears in each row. Note that the Count field appears only after you apply a constraint that creates two or more identical rows. This field is not searchable.
Remediation Status Events
When a remediation triggers, the system logs a remediation status event to the database. These events can be viewed on the Remediation Status page. You can search, view, and delete remediation status events.
- Viewing Remediation Status Events
- Remediation Status Table Fields
- Using the Remediation Status Events Table
Viewing Remediation Status Events
|
Smart License |
Classic License |
Supported Devices |
Supported Domains |
Access |
|---|---|---|---|---|
|
Any |
Any |
Any |
Any |
Admin |
The page you see when you access remediation status events differs depending on the workflow you use. You can use the predefined workflow, which includes a table view of remediations. The table view contains a row for each remediation status event. You can also create a custom workflow that displays only the information that matches your specific needs.
In a multidomain deployment, you can view data for the current domain and for any descendant domains. You cannot view data from higher level or sibling domains.
| Step 1 | Choose . | ||
| Step 2 | Optionally, adjust the time range as described in Changing the Time Window. | ||
| Step 3 | Optionally, to use a different workflow, including a custom
workflow, click
(switch workflow) by the workflow title.
| ||
| Step 4 | You have the following options:
|
Remediation Status Table Fields
The following table describes the fields in the remediation status table that can be viewed and searched.
Using the Remediation Status Events Table
|
Smart License |
Classic License |
Supported Devices |
Supported Domains |
Access |
|---|---|---|---|---|
|
Any |
Any |
Any |
Any |
Admin |
You can change the layout of the event view or constrain the events in the view by a field value.
When you disable a column, it is disabled for the duration of your session unless you add it back later. If you disable the first column, the Count column is added.
Clicking a value within a row in a table view constrains the table view and does not drill down to the next page.
![]() Tip | Table views always include “Table View” in the page name. |
In a multidomain deployment, you can view data for the current domain and for any descendant domains. You cannot view data from higher level or sibling domains.
| Step 1 | Choose
.
| ||
| Step 2 | You have the following options:
|


Feedback