show fenet security-content status

Prev Next

Displays the status of the security content installed on the appliance or the status of the latest action taken on security content updates.

Syntax

show fenet security-content status [progress]

Parameters

progress

(Optional) Display status of the latest action taken on security content updates. The output displays the status of any of the following actions:

  • check-update—Check for a new security-content package.

  • download-update—Download the latest security-content package.

  • apply-update—Update the appliance to the downloaded security-content.

  • upload—Configure Trellix security-content sharing.

If this option is not used, the output displays the status of the security content installed on the appliance.

Output fields

When the progress parameter is used, the command output displays the status of the latest action taken on security content updates. Examples:

  • check-info: No new security updates available

  • apply-info: No new security contents detected on this system

  • apply-info: Downloaded updates already installed

When the progress parameter is not used, the command output displays detailed information about the status of security content.

The following table describes the command output fields.

Field Name

Field Description

Dynamic Threat Intelligence Service

Update source

DTI update source (download server) status:

  • <online>

  • <offline>

Update channel

Name of the DTI download server channel

Enabled

DTI download server configuration status:

  • yes—Configured

  • no—Not configured

Address

Description of the DTI download source:

<serverType> (<serverIP> : <addrType>)

<serverType>—DTI download source type:

  • CDN—Content Distribution Network

  • CMSCentral Management System appliance

  • DTI—DTI Cloud

<serverIP>—DTI update source IP address

<addrType>—(If <serverType> is CMS) Type of address that the managed appliance uses to request software updates from the DTI update source:

  • auto—(Default) Management traffic uses the SSH port and DTI network traffic uses an HTTPS port.

  • singleport—All traffic uses the SSH port. This simplifies the complexity of firewall rules and Network Address Translation (NAT) mapping.

Username

Username of an account that has appropriate access privileges on the DTI update server.

SC acceptance level

Acceptable level for security content on this appliance.

SC type connected

Appliance connectivity to the Internet:

  • yes—Connected

  • no—Disconnected

SC channel version

Name and version of the DTI Offline Update Portal channel that provides the security content for the appliance. This channel is specific to the appliance model and software release number.

NOTE: The SC channel applies only to appliances that are disconnected from the Internet. For details, see the DTI Update Portal User Guide .

Online Analysis Service

Service available

Online analysis service:

  • yes—Available

  • no—Unavailable

AV-Suite enabled

AV-suite analysis:

  • yes—Enabled

  • no—Disabled

NOTE: This field does not apply to Central Management System appliances.

Local Security Content Auto-Generate

Enabled

Autogeneration of local security content:

  • yes—Enabled

  • no—Disabled

Infections enabled

Autogeneration of local security content based on infection-match events:

  • yes—Enabled

  • no—Disabled

Callbacks enabled

Autogeneration of local security content based on malware callback events:

  • yes—Enabled

  • no—Disabled

Security Content Autoupdate

Enabled

Security content automatic updates:

  • yes—Security content is updated automatically

  • no—Security content is updated manually

Action

Autoupdate action scheduled:

  • check with upload—Check for automatic updates but do not update

  • update with upload—Apply automatic updates

Warn outdated after

The security content age, in hours, after which the content is deemed outdated.

For more information, see the "Warnings for Outdated Security Content" section of the Administration Guide or System Administration Guide for your Trellix appliance.

NOTE: This field is supported on Central Management System 7.9.2, Email Security — Server 7.9.0, Endpoint Security (HX) 3.3, and Network Security 7.9.2 releases and earlier.

Notify (uploads)

Email notifications for security content sharing:

  • yes—Enabled

  • no—Disabled

Notify (downloads)

Email notifications for security content autoupdates:

  • yes—Enabled

  • no—Disabled

Scheduled

Frequency of security content autoupdate intervals

Security Content Uploads

Enabled

Security content sharing:

  • yes—Enabled

  • no—Disabled

Last Uploaded At

Appliance date and time when security content was most recently shared.

Status

The most recent security content-sharing activity and its status. Example:

apply-info: No new security contents detected

Security Content Updates (does not apply to Central Management System appliances)

Enabled

Security content updates:

  • yes—Enabled

  • no—Disabled

Last Checked At

Appliance date and time of the most recent check for new security content.

Last Applied At

Appliance date and time of the most recent application of new security content.

Timestamp (UTC)

The date and time stamp, shown in UTC format, that was written to the security content metadata when the package was created. The appliance uses this timestamp to determine whether the installed security content is outdated.

For more information, see "Warnings for Outdated Security Content" in the System Administration Guide for your Trellix appliance.

NOTE: This field is supported on Email Security — Server 7.9.0, Endpoint Security (HX) 3.3, and Network Security 7.9.2 releases and earlier.

Status

Status of the most recent checking for new security content applying new security content. Examples:

  • check-info: No new security updates available

  • apply-info: Downloaded updates already installed

WARNING

Security contents are OUTDATED.

This warning message appears only if the installed security content is outdated. In the Web UI, a warning message appears at the top of the Dashboard. Email Security — Server and Network Security appliances also send email notifications (if configured) to SMTP recipients.

For more information, see "Warnings for Outdated Security Content" in the System Administration Guide for your Trellix appliance.

NOTE: This feature is supported on Email Security — Server 7.9.0, Endpoint Security (HX) 3.3, and Network Security 7.9.2 releases and earlier.

Security Content Version (does not apply to Central Management System appliances)

Security Content Version

Version number of the installed security content.

Example: 544.292

Example

In the following example, the command output shows the security-content status for a Central Management System appliance.

hostname # show fenet security-content status

DTI Security Content Status Information:

  Dynamic Threat Intelligence Service
    Update source        : <online>
    Update channel       : stable
    Enabled              : yes
    Address              : DTI (cloud.fireeye.com)
    Username             : DTIUser
    SC acceptance level  : stable
    SC type connected    : yes
    SC channel version   : SCCMS-1.0

  Online Analysis Service:
    Service available    : yes

  Local Security Content Auto-Generate:
    Enabled              : yes
    Infections enable    : yes
    Callbacks enabled    : yes

  Security Content Autoupdate
    Enabled              : yes
    Action               : update with upload
    Warn outdated after  : 5 hours
    Notify (uploads)     : no
    Notify (downloads)   : no
    Scheduled            : every 15 minutes

  Security Content Uploads
    Enabled              : yes
    Last Uploaded At     : Never
    Status               : upload-info: No new security contents detected on this system

User role

Admin, Analyst, Monitor, and Operator

Command mode

Enable

Supported appliances

This command is supported on the following appliances running the specified releases or later:

  • Malware Analysis: Before release 6.4

  • Central Management System: Before release 6.4

  • Email Security — Server: Before release 6.4

  • Endpoint Security (HX): Release 2.5

  • File Protect: Before release 6.4

  • Network Security: Before release 6.4

  • Intelligent Virtual Execution - Server: Release 7.9