fenotify preferences normalize-ips-event enable

Prev Next

By default, alert notifications use src/smac/sport for the network traffic source and use dst/dmac/dport as the network traffic destination. This command changes alert notifications to use src/smac/sport as the network traffic destination (victim) and use dst/dmac/dport as the network traffic source (attacker). This command affects all notification data formats. This command applies only to IPS-enabled appliances (Network Security and Central Management System).

Syntax

[no] fenotify preferences normalize-ips-event enable

Parameters

no

Use the no form of this command to change alert notifications to use src/smac/sport as the network traffic destination (victim) and use dst/dmac/dport as the network traffic source (attacker).

Example

The following example returns alert notifications to the default, using src/smac/sport for the network traffic source and using dst/dmac/dport as the network traffic destination:

hostname (config) # fenotify preferences normalize-ips-event enable

User role

Admin and Operator

Command mode

Config

Supported appliances

This command is supported on the following appliances running the specified releases or later:

  • Central Management System: Release 7.8

  • Endpoint Security (HX): Release 3.5.0

  • Network Security: Release 7.8