Prerequisites
Ensure that you are running management center 7.2.0 or later and that the managed threat defense is also 7.2.0 or later.
When you enable only elephant flow detection, no additional connection events are generated. The system adds the Elephant Flow notation to matching connections that are already logged to the management center. To log these events, you must enable connection logging in your access control policy. You can do that for specific rules or add a Monitor rule that logs all connections, including elephant flows.