Displays the status of the security content installed on the appliance or the status of the latest action taken on security content updates.
Syntax
show fenet security-content status [progress]
Parameters
progress
(Optional) Display status of the latest action taken on security content updates. The output displays the status of any of the following actions:
check-update—Check for a new security-content package.download-update—Download the latest security-content package.apply-update—Update the appliance to the downloaded security-content.upload—Configure Trellix security-content sharing.
If this option is not used, the output displays the status of the security content installed on the appliance.
Output fields
When the progress parameter is used, the command output displays the status of the latest action taken on security content updates. Examples:
check-info: No new security updates availableapply-info: No new security contents detected on this systemapply-info: Downloaded updates already installed
When the progress parameter is not used, the command output displays detailed information about the status of security content.
The following table describes the command output fields.
Field Name | Field Description |
|---|---|
Dynamic Threat Intelligence Service | |
Update source | DTI update source (download server) status:
|
Update channel | Name of the DTI download server channel |
Enabled | DTI download server configuration status:
|
Address | Description of the DTI download source:
|
Username | Username of an account that has appropriate access privileges on the DTI update server. |
SC acceptance level | Acceptable level for security content on this appliance. |
SC type connected | Appliance connectivity to the Internet:
|
SC channel version | Name and version of the DTI Offline Update Portal channel that provides the security content for the appliance. This channel is specific to the appliance model and software release number. NOTE: The SC channel applies only to appliances that are disconnected from the Internet. For details, see the DTI Update Portal User Guide . |
Online Analysis Service | |
Service available | Online analysis service:
|
AV-Suite enabled | AV-suite analysis:
NOTE: This field does not apply to Central Management System appliances. |
Local Security Content Auto-Generate | |
Enabled | Autogeneration of local security content:
|
Infections enabled | Autogeneration of local security content based on infection-match events:
|
Callbacks enabled | Autogeneration of local security content based on malware callback events:
|
Security Content Autoupdate | |
Enabled | Security content automatic updates:
|
Action | Autoupdate action scheduled:
|
Warn outdated after | The security content age, in hours, after which the content is deemed outdated. For more information, see the "Warnings for Outdated Security Content" section of the Administration Guide or System Administration Guide for your Trellix appliance. NOTE: This field is supported on Central Management System 7.9.2, Email Security — Server 7.9.0, Endpoint Security (HX) 3.3, and Network Security 7.9.2 releases and earlier. |
Notify (uploads) | Email notifications for security content sharing:
|
Notify (downloads) | Email notifications for security content autoupdates:
|
Scheduled | Frequency of security content autoupdate intervals |
Security Content Uploads | |
Enabled | Security content sharing:
|
Last Uploaded At | Appliance date and time when security content was most recently shared. |
Status | The most recent security content-sharing activity and its status. Example:
|
Security Content Updates (does not apply to Central Management System appliances) | |
Enabled | Security content updates:
|
Last Checked At | Appliance date and time of the most recent check for new security content. |
Last Applied At | Appliance date and time of the most recent application of new security content. |
Timestamp (UTC) | The date and time stamp, shown in UTC format, that was written to the security content metadata when the package was created. The appliance uses this timestamp to determine whether the installed security content is outdated. For more information, see "Warnings for Outdated Security Content" in the System Administration Guide for your Trellix appliance. NOTE: This field is supported on Email Security — Server 7.9.0, Endpoint Security (HX) 3.3, and Network Security 7.9.2 releases and earlier. |
Status | Status of the most recent checking for new security content applying new security content. Examples:
|
WARNING |
This warning message appears only if the installed security content is outdated. In the Web UI, a warning message appears at the top of the Dashboard. Email Security — Server and Network Security appliances also send email notifications (if configured) to SMTP recipients. For more information, see "Warnings for Outdated Security Content" in the System Administration Guide for your Trellix appliance. NOTE: This feature is supported on Email Security — Server 7.9.0, Endpoint Security (HX) 3.3, and Network Security 7.9.2 releases and earlier. |
Security Content Version (does not apply to Central Management System appliances) | |
Security Content Version | Version number of the installed security content. Example: 544.292 |
Example
In the following example, the command output shows the security-content status for a Central Management System appliance.
hostname # show fenet security-content status DTI Security Content Status Information: Dynamic Threat Intelligence Service Update source : <online> Update channel : stable Enabled : yes Address : DTI (cloud.fireeye.com) Username : DTIUser SC acceptance level : stable SC type connected : yes SC channel version : SCCMS-1.0 Online Analysis Service: Service available : yes Local Security Content Auto-Generate: Enabled : yes Infections enable : yes Callbacks enabled : yes Security Content Autoupdate Enabled : yes Action : update with upload Warn outdated after : 5 hours Notify (uploads) : no Notify (downloads) : no Scheduled : every 15 minutes Security Content Uploads Enabled : yes Last Uploaded At : Never Status : upload-info: No new security contents detected on this system
User role
Admin, Analyst, Monitor, and Operator
Command mode
Enable
Supported appliances
This command is supported on the following appliances running the specified releases or later:
Malware Analysis: Before release 6.4
Central Management System: Before release 6.4
Email Security — Server: Before release 6.4
Endpoint Security (HX): Release 2.5
File Protect: Before release 6.4
Network Security: Before release 6.4
Intelligent Virtual Execution - Server: Release 7.9