fenotify alert <alertType> enable

Prev Next

Globally enables and disables all supported Trellix event notifications for the specified alert type.

Note

You can also run this command remotely from the command line of an integrated TrellixCentral Management System appliance using the central management appliance proxying mechanism.

Syntax

[no] fenotify alert <alertType> enable

Parameters

no

Use the no form of this command to disable notification alerts for the specified alert type.

<alertType>

The following <alertType> options are available, depending on the Trellix product.

Type

Description

Supported

Products

domain-match

Notification of domain-match event.

Central Management System, Network Security

exploit-blocked

Notification that an exploit was prevented (blocked) by Exploit Guard.

HX Series

exploit-detected

Notification that an exploit was detected by Exploit Guard. Notifications are not sent for exploits that have been prevented (blocked).

HX Series

indicator-executed

Notification of the execution of an indicator of condition (IOC).

HX Series

indicator-presence

Notification of the presence of an indicator of condition (IOC). Notifications are sent for indicators that are present in the environment, including those that have executed.

HX Series

infection-match

Notification of infection-match events.

Central Management System, Network Security

ips-event

Notification of an IPS event. Supported on MVX IPS-enabled appliances only.

Central Management System, Network Security

malware-callback

Notification of malware callback events.

Central Management System, Network Security

malware-object

Notification of malware object events.

Central Management System, Network Security

riskware-callback

Notification of malware object events.

Central Management System, EX Series, Network Security

riskware-infection

Notification of riskware infection events.

Central Management System, Network Security

riskware-object

Notification of malware object events.

Central Management System, EX Series, Network Security

smartvision-event

(On a SmartVision appliance) Notification of SmartVision events by supported Trellix event notification methods.

Central Management System, Network Security

web-infection

Notification of Web infection events.

Central Management System, EX Series, Network Security

Example

The following example enables alert notifications for malware callback events.

hostname (config)# fenotify alert malware-callback enable

User role

Admin or Operator

Command mode

Configuration

Supported appliances

This command is supported on the following appliances running the specified releases or later:

Central Management System: Before Release 7.6.0

Endpoint Security (HX): Release 3.5.0

Network Security: Before Release 7.6.0