l7metadata-export enable

Prev Next

Enables or disables the Layer 7 Metadata Event Exporter to collect logs generated by the TrellixNetwork Security appliance. When you enable the Layer 7 Metadata Event Exporter on the appliance, the appliance sends the network event logs to the Splunk Enterprise platform that you specified to perform further analysis. When you disable the Layer 7 Metadata Event Exporter on the appliance, the appliance does not send the network event logs to the Splunk Enterprise platform.

Note

You cannot integrate a SmartVision Edition sensor with a Splunk Enterprise server. SmartVision Edition sensors do not support the Layer 7 Metadata Event Exporter feature.

Note

Splunk integration is not supported on the NX x3xx appliances and the NX 10000 appliance.

Caution

When the Layer 7 Metadata Event Exporter is enabled on the NX 4400 appliance models and above, peak throughput may be degraded by 10% to 15%.

When the Layer 7 Metadata Event Exporter is enabled on the NX 2500 appliance models and below, peak throughput may be degraded by 15% to 20%.

Syntax

[no] l7metadata-export enable

Parameters

no

Use the no form of this command to disable the Layer 7 Metadata Event Exporter.

Examples

The following example enables the Layer 7 Metadata Event Exporter.

hostname (config) # l7metadata-export enable
Enabling l7metadata-export

The following example disables the Layer 7 Metadata Event Exporter.

hostname (config) # no l7metadata-export enable
Disabling l7metadata-export

User role

Admin or Operator

Command mode

Config

Supported appliances

This command is supported on the following appliances running the specified releases or later:

  • Network Security: Release 8.2