About the Web UI tabs

Prev Next

The Email Security - Server Web UI contains the following tabs. Widgets on theTrellix default dashboard are now categorised into multiple tabs for better interface performance and user experience.

Tab

Description

Dashboard

Overview of threat intelligence gathered by the appliance. See “The Appliance Dashboard” in the Email Security — Server System Administration Guide.

eAlerts

Details about malware attacks, aggregated alerts, and analysis results.

eQuarantine

View all information about emails in the quarantine. Release or delete the emails from the quarantine.

Search Emails

Search all emails that have been processed by the appliance. View and manage the emails that are being processed or placed in the queue by the appliance.

Settings

Appliance and threat management settings:

Date and Time—Configure the date and time or specify one or more NTP servers.

User Accounts—Manage user accounts, including passwords, role assignments, and local access status, and reset your own password if you are assigned the Administrator role.

Email—Configure the appliance email account used for system notifications.

DTI Network—Specify the frequency of security and statistical content uploads.

CMS Network—Initiate a request to be added to the Central Management System platform.

Notifications—Configure and test event notifications for analysis alerts.

Network—View management interface settings. Configure DNS (Domain Name Service) settings.

Email MTA—Configure the SMTP interface, domain and next-hop settings, TLS (Transport Layer Security) settings, email bounce settings, network connectivity settings for pether2 that are shared between URL Dynamic Analysis and Controlled Live mode, and congestion control settings.

Email Policy—Configure the analysis mode, quarantine settings, and detection notifications. Enable feature settings.

Impersonation—Configure sender impersonation detection rules.

Advanced URL Defense—Identify suspicious URLs that are embedded in an email message. The appliance sends a request to the DTI Cloud to perform an analysis of the suspicious URLs.

YARA Rules—Upload byte-level rules that quickly analyze large quantities of files.

Riskware Policy—Enable the riskware detection feature. Enable policy rules based on custom riskware detection. Enable blocking policy rules based on custom riskware detection.

Guest Images—View information about the currently loaded guest images (virtual machines) that test traffic and software for malicious activity.

Certificates/Keys—Upload SSL certificates.

Allowed List—Configure rules to control which messages can be bypassed based on the matched email entries.

Blocked List—Configure rules to control which messages must be considered malicious based on the matched email entries.

Attachment decryption—Configure passwords, keywords, and ignored words on a candidate list for password extraction.

Appliance Backup and Restore—Perform backup and restore operations for the appliance database.

Appliance Licenses—Install and remove licenses.

Login Banner—Configure the banner text displayed when a user logs in to the CLI or Web UI.

Increased Detection—Send additional information to Trellix for analysis to increase detection rates.

Data Retention Policy - Configure number of days to retain appliance data and schedule purging frequency.

Reports

Generate or schedule consolidated reports in various output formats.

About

Network administration information and controls:

Summary—Displays system information, such as software version and Security Contents version.

Supported Features—Displays features available for the appliance and whether they are enabled or disabled.

Health Check—Provides comprehensive and current system status information such as software version, patch version, content version, services health information, MVX engine version, DTI connection, and configured interfaces.

Log Manager—Allows you to manage system logs.

Upgrade—Allows you to check for and install new security content, appliance image, and guest images.

PDF generation

Some Web UI pages, such as those that display analysis results, have a Print PDF button at the top right side of the page that allows you to save the content of the page to PDF so it can be printed or saved. Only the content that is visible on the page is included in the PDF output. For example, if an item on the page is not expanded, the details about that item are not displayed and will not be included in the PDF output. Depending on your Web browser settings, the generated PDF opens in the Web browser or is downloaded to your computer.

The amount of time needed to generate the PDF depends on the current load on the system. By default, the system will try to generate the PDF using Standard Processing Time, the fastest way possible. If the PDF generation times out, you can try again using other options by clicking the arrow on the button and then selecting Extra Processing Time or Heavy Processing Time, where heavy processing time takes the longest.

All_PDFOptions_Scap.png