fenotify http service <service-name> prefer notification

Prev Next

Configures the type of alerts for which HTTP notification should occur for the specified service.

Syntax

[no] fenotify http service <service-name> prefer notification <event-type>

Parameters

no

Use the no form of this command to remove the configuration options currently set.

service-name

A convenient name (nickname) for the Trellix notification consumer of the service.

event-type

Configure notifications for a specific class of alerts. Some of these will be available, depending on your Trellix product.

Type

Description

Supported products

domain-match

Notification of domain-match event.

Malware Analysis, Email Security — Server, Network Security

exploit-blocked

Notification that an exploit was prevented (blocked) by Exploit Guard.

Endpoint Security (HX)

exploit-detected

Notification that an exploit was detected by Exploit Guard. Notifications are not sent for exploits that have been prevented (blocked).

Endpoint Security (HX)

indicator-executed

Notification of the execution of an indicator of condition (IOC).

Endpoint Security (HX)

indicator-presence

Notification of the presence of an indicator of condition (IOC). Notifications are sent for indicators that are present in the environment, including those that have executed.

Endpoint Security (HX)

infection-match

Notification of infection-match events.

Malware Analysis, Email Security — Server, Network Security

ips-event

Notification of an IPS event. Supported on MVX IPS-enabled platforms only.

Malware Analysis, Email Security — Server, Network Security

malware-callback

Notification of malware callback events.

Malware Analysis, Email Security — Server, Network Security

malware-infection

Notification of Web infection events.

Malware Analysis, Email Security — Server, Network Security

malware-object

Notification of malware object events.

Malware Analysis, Email Security — Server, Network Security

Example

The following example sets the type of alerts for which HTTP notification should occur for service test to exploit-detected:

hostname (config) # fenotify http service test prefer notification exploit-detected

User role

Admin, Operator, Analyst

Command mode

Config

Supported appliances

  • Malware Analysis: Before Release 6.3

  • Email Security — Server: Before Release 6.3

  • Endpoint Security (HX): Release 3.5.0

  • Network Security: Before Release 6.3