Skip to content

FTD - Firepower Threat Defense

Overview

Cisco Firepower Threat Defense provides firewall and threat-defense functions on the live network path.

Monitoring

Method

Prometheus SNMP Exporter through network-prometheus.

Metrics Collected

  • HA and device state
  • Interface, route, VPN, connection, and drop indicators
  • CPU, memory, and system health
  • SNMP target and scrape health

Grafana Dashboards

Logging

Log Source

FTD and Firepower devices forward firewall syslog and SNMP traps.

Splunk Index

firewall_syslog for syslog and snmp_traps for traps.

Key Log Queries

index=firewall_syslog node_type IN ("ftd","firepower") device_name="<device_name>"

Alerting

Grafana Alert Rules

Alert Name Severity Description
FTD device health Varies Firewall, interface, and resource conditions.
Scrape down Critical Detects loss of FTD SNMP collection.

Splunk Alerts

Alert Name Severity Description
FTD firewall events Varies Security and device events from firewall_syslog.

Notification Flow

FTD → Grafana/Splunk → EMS (KeepHQ) → [notification channels]

Inventory

  • Repository: ftd-firepower-inventory
  • Update Method: Generated from the managed FTD/Firepower Ansible inventory, with documented manual FMC entries.
  • Update Cadence: On inventory change through pull request.