show fenotify integ helix

Prev Next

Displays Helix Enterprise event notification settings.

Syntax

show fenotify integ helix

Parameters

None

Output fields

The following table describes the output fields for this command.

Note

Unless otherwise noted, the output fields represent settings that are not customer-configurable.

Field

Description

enable

Whether alerts can be sent to Helix Enterprise.

config source

Indicates whether Helix Enterprise integration auto-configuration is enabled.

  • RDS: Auto-configuration through the Registry and Discovery Service is enabled.

  • LOCAL: Auto-configuration is disabled

path

The path to the Helix Enterprise alert ingestion URI.

port

The HTTPS port through which the appliance sends alerts to Helix Enterprise.

hostname

The fully qualified domain name (FQDN) that represents the alert ingestion URI.

protocol

HTTPS, the protocol through which the appliance sends alert to Helix Enterprise.

Helix Full URL

The Helix Enterprise full alert ingestion URL.

userName

The username used to authenticate to the Helix Enterprise server (N/A by default).

passCode

The passcode used to authenticate to the Helix Enterprise server (N/A by default).

ssl-verify

Whether SSL verification is enabled.

verbose-mode

Whether verbose logging is enabled.

apply-fenet-settings

Whether DTI connection settings are applied to the connection between the appliance and the Helix Enterprise ingestion URI. (The default setting is true on supported appliances. To change this setting, use the [no] fenotify integ helix apply-fenet-config enable command.)

max alert retry TTL

The number of days the appliance will continue to re-send alerts to Helix Enterprise after delivery failure. (The default setting is 20 days. To change this setting, use the fenotify integ helix max ttl <number> command.)

include os-changes

Whether alerts should include information about OS changes. (The default setting is true. To change this setting, use the [no] fenotify integ helix include-oschanges enable command.)

malware object

Whether malware object alerts should be sent to Helix Enterprise.

malware callback

Whether malware callback alerts should be sent to Helix Enterprise.

web infection

Whether Web infection alerts should be sent to Helix Enterprise.

infection match

Whether infection match alerts should be sent to Helix Enterprise.

domain match

Whethter domain match alerts should be sent to Helix Enterprise.

IPS event

Whether IPS event alerts should be sent to Helix Enterprise.

riskware object

Whether riskware object alerts should be sent to Helix Enterprise.

riskware callback

Whether riskware callback alerts should be sent to Helix Enterprise.

smartvision event

Whether SmartVision event alerts should be sent to Helix Enterprise. (Network Security only)

Example

The following example displays Helix Enterprise integration notification settings on a Central Management System appliance.

hostname # show fenotify integ helix
Helix Integration Notification Settings:
=====================================================
enable                   :    yes
config source            :    LOCAL
path                     :    receiver.jsp
port                     :    443
hostname                 :    xyz.it.acme.com
protocol                 :    https
Helix Full URL           :    https://xyz.it.acme.com:8443/receiver.jsp
userName                 :    N/A
passCode                 :    N/A
ssl-verify               :    true
verbose-mode             :    false
apply-fenet-settings     :    true
max alert retry TTL      :    20 days
include os-changes       :    true
=====================================================
alert status:
malware object      :    yes
malware callback    :    yes
web infection       :    yes
infection match     :    yes
domain match        :    yes
IPS event           :    yes
riskware object     :    yes
riskware callback   :    yes
smartvision event   :    yes
=====================================================

User role

Admin, Operator, Monitor, or Analyst

Command mode

Enable

Supported appliances

This command is supported on the following appliances running the specified releases or later:

  • Malware Analysis: Release 8.1.0

  • Central Management System: Release 8.2.0

  • Email Security — Server: Release 8.1.0

  • File Protect: Release 8.1.0

  • Endpoint Security (HX): Release 4.5.0

  • Network Security: Release 8.1.0

  • Intelligent Virtual Execution - Server: Release 8.1.0