FMC - Firepower Management Center
Overview
Cisco Firepower Management Center provides the management and policy-control plane for Firepower security devices.
Monitoring
Method
Prometheus SNMP Exporter through network-prometheus.
Metrics Collected
- FMC system and service health
- Managed-device and policy status indicators
- Interfaces, CPU, memory, and storage
- SNMP target and scrape health
Grafana Dashboards
Logging
Log Source
FMC-related firewall syslog and SNMP traps are sent through the regional ingress services.
Splunk Index
firewall_syslog for syslog and snmp_traps for traps.
Key Log Queries
index=firewall_syslog node_type="fmc" device_name="<device_name>"
Alerting
Grafana Alert Rules
| Alert Name | Severity | Description |
|---|---|---|
| FMC device health | Varies | Management-plane and platform conditions. |
| Scrape down | Critical | Detects loss of FMC SNMP collection. |
Splunk Alerts
| Alert Name | Severity | Description |
|---|---|---|
| FMC security events | Varies | Management and security events from firewall_syslog. |
Notification Flow
FMC → Grafana/Splunk → EMS (KeepHQ) → [notification channels]
Inventory
- Repository: ftd-firepower-inventory
- Update Method: FMC targets are documented as manual inventory additions.
- Update Cadence: When FMC inventory changes.