DDI has been deployed for several days but it has not generated logs for any threat. This is experienced by customers who are using Cisco Encapsulated Remote Switching Port Analyser (ERSPAN) to mirror the traffic to DDI.
The issue occurs because there is a misconfiguration in the ERSPAN setting and the mirrored packets are malformed.
You can use a packet analysis software, such as Wireshark, to confirm if packets are broken.
To resolve the issue, contact CISCO support to help in reconfiguring ERSPAN and make sure that the packets redirected to DDI are not malformed.