FTD - Firepower Threat Defense
Overview
Cisco Firepower Threat Defense provides firewall and threat-defense functions on the live network path.
Monitoring
Method
Prometheus SNMP Exporter through network-prometheus.
Metrics Collected
- HA and device state
- Interface, route, VPN, connection, and drop indicators
- CPU, memory, and system health
- SNMP target and scrape health
Grafana Dashboards
Logging
Log Source
FTD and Firepower devices forward firewall syslog and SNMP traps.
Splunk Index
firewall_syslog for syslog and snmp_traps for traps.
Key Log Queries
index=firewall_syslog node_type IN ("ftd","firepower") device_name="<device_name>"
Alerting
Grafana Alert Rules
| Alert Name | Severity | Description |
|---|---|---|
| FTD device health | Varies | Firewall, interface, and resource conditions. |
| Scrape down | Critical | Detects loss of FTD SNMP collection. |
Splunk Alerts
| Alert Name | Severity | Description |
|---|---|---|
| FTD firewall events | Varies | Security and device events from firewall_syslog. |
Notification Flow
FTD → Grafana/Splunk → EMS (KeepHQ) → [notification channels]
Inventory
- Repository: ftd-firepower-inventory
- Update Method: Generated from the managed FTD/Firepower Ansible inventory, with documented manual FMC entries.
- Update Cadence: On inventory change through pull request.