We had to solve this (and similar problems with the Sensors). We had sensors that would quietly crash and nobody would notice until blank reports started showing up. Embarrassed that significant periods of time could go by without noticing that a sensor didn't have any traffic to process we created a "heartbeat" custom signature that would fire on any traffic with a 5 min summary. Our SIM them watches for a few consecutive missed heartbeat signatures from each sensor before alerting our Operations team.
This does require some external elements to work, but it has the benefit of monitoring the entire event communications chain, from sensing to reporting. If anything breaks, you'll know about it.
We asked Cisco to create a standard signature for heartbeat, and it was an approved Cisco feature back in early 6.x days, but it got pulled before being implemented.
However, I was challenged to find a solution on the switch because even with your approach (heartbeat signature), it wouldn't fully work with a switch that would have multiple SPAN configured on it. One can still disabled a particular port and the rest of the SPAN would still be operational in sending traffic to the IPS. In fact, it is this kind of scenario I'd like to detect. That's why in the first place I brought my question around to the switch's configuration. (but again maybe it is not the right place to ask this - perhaps in the Network Infrastructure forum?)
DocumentationCode download linksGoalRequirementLimitationsSupported ISR and UCS-E ModelSupported ISRG2 and UCS-E Blades:Supported ISR4K and UCS-E Blades:Step by Step ConfigurationConfigure one of the connectivity options to access the Cisco IMC from the n...
Firepower Threat Defense (NGFWv) on UCS E-series - Transparent Mode in HA
DocumentationCode download linksGoalRequirementLimitationsSupported ISR and UCS-E ModelSupported ISRG2 and UCS-E Blades:Supported ISR4K and UCS-E Blades:Step by Step ConfigurationCo...
I am currently unable to specify "crypto keyring" command when configuring VPN connection on my cisco 2901 router.
The following licenses have been activated on my router :