Enables and disables the generation of Endpoint Security (HX) execution indicators from Network Security, Email Security — Server, File Protect, and Malware Analysis appliance alerts, which include alerts on malware callback traffic and host infections. These execution indicators are also referred to as noisy alert indicators.
False positives may occur when Endpoint Security (HX) noisy alert indicators are enabled. False positives include commonly visited domains that are not malicious, false positive registry entries, and file MD5 indicators. Enable the generation of noisy alert indicators if you can manage the possibility of false positives. They are disabled by default.
Syntax
[no] hx server detection legacy noisy-indicator enable
Parameters
no
Disables noisy alert indicators.
Example
The following example enables noisy alert indicators:
hostname (config) # hx server detection legacy noisy-indicator enable
User role
Admin
Command mode
Config
Supported appliances
This command is supported on the following appliances running the specified releases or later:
Endpoint Security (HX): Release 2.5