Enables riskware notifications through rsyslog using the transmission control protocol (TCP) and user datagram protocol (UDP).
When you enable riskware notifications, notifications are sent for both riskware-object and riskware-callback events on Network Security and Central Management System appliances and from security information and event management (SIEM) software products. When you disable riskware notifications, notifications are not sent for riskware-object or riskware-callback events on Network Security or Central Management System appliances or from SIEM software products.
The common event format (CEF), log event enhanced format (LEEF), extensible markup language (XML) and JavaScript object notation (JSON) are supported.
Syntax
[no] fenotify preferences support-riskware enable
Parameters
no
Use the no form of this command to disable riskware notifications.
Example
The following example enables riskware notifications:
hostname (config) # fenotify preferences support-riskware enable
User role
Admin and Operator
Command mode
Config
Supported appliances
This command is supported on the following appliances running the specified releases or later:
Central Management System: Release 7.9.1
Email Security — Server: Release 8.0.0
Network Security: Release 7.9.1