How to Find an Original Source IP in Cisco Firepower when the hosts are behind a WSA
If your WSA is configured to send original client information, you can find this very useful information in the FMC Analysis>Connection Events output, and make rules in your ACP using this information.
To find an original source IP address of hosts located inside the FMC connection events output, but the hosts are behind a WSA for example, use the following steps on your Cisco FMC:
3. Click on any of the the black circles where you want the new column showing the original source IP’s to appear:
Notice the new entries available to either delete or approve as column for this view.