Enables object extraction on the Evidence Collector edition Network Security sensor. After object extraction is enabled, the MVX CLI tree on the Evidence Collector edition is displayed and the MVX submission client is started. As a result of this, the Network Security appliance automatically enrolls to Intelligent Virtual Execution - Server cluster and sends submissions. The CLI loads only the object extraction (BA) rules when object extraction is enabled. Therefore, the CLI does not extract/submit any web infection objects. If you want to submit only the object extraction rules for EC, use the following files provided under suricata/rules:
ec-fume_suricata.rules: This file contains only object extraction rules (subset of suricata.rules). It is available as suricata.rules for Evidence Collector object-extract enable case.
ec-websocket.rules: This file contains object extraction rules for WebSocket (subset of websocket.rules) only. It is available as websocket.rules.
To verify that object extraction is enabled, run the following commands:
Evidence Collector Edition: object-extract support: yes
Note
These files are loaded in foxd when object-extract enable CLI is triggered.
Syntax
foxd config object-extract enable
Parameters
no
Disables object extraction on the NX sensor.
Example
The following example enables object extraction on the appliance:
hostname (config) # foxd config object-extract enableUser roles
Admin and Operator
Command mode
Config
Supported appliances
This command is supported on the following appliances running the specified releases or later:
Network Security:Release 10.0 or later in Evidence Collector edition Network Security sensors
Central Management System:Release 10.0 or later in Evidence Collector edition Network Security sensors