While the botnet filter feature license* is inexpensive (Approx $1000 US per ASA per year), I am not completely sold on the viability of the product. The 'client updater' checks for updates at the ironport site every five minutes or so but the database version has not changed since Nov 4 when the database was first fetched, which leads me to believe that no updates have occurred. I would think that with the ever changing (and growing) landscape of botnets that this database would be changing all the time. I may just be looking at this incorrectly. I am wondering if anyone else has similar feedback
*Feature available on 8.2 and higher code.