Displays customized preferences for Trellix event notifications.
This command also displays information about IPS event notification delivery mode, delivery option for HTTP or HTTPS notifications, a delivery option for Rsyslog notifications.
Note
You can also run this command remotely from the command line of an integrated Trellix Central Management System appliance using the Central Management System appliance proxying mechanism.
Syntax
show fenotify preferences
Parameters
None
Output fields
The following table describes the output fields for the show fenotify preferences command. Fields are listed in the approximate order in which they appear in the output.
Field Name | Description |
|---|---|
IPS delivery mode | Delivery mode for IPS event notifications:
|
HTTP(s) notification using fenet proxy | Delivery mode for event messages posted to Web servers using HTTP or HTTPS:
You can use the following CLI commands to configure the system to pst event messages to Web servers using HTTP or HTTPS: |
Rsyslog notification Stripping off line feedback | Delivery option to strip off line feedback for event notifications sent to a remote syslog server:
You can use the following CLI commands to configure the system to send event notifications to a remote syslog server: |
SIEM Riskware support | Notification option:
|
Normalize IPS Event | Notification data format:
|
Notification CPU-Sender Ratio | Use the |
Smart Vision Event Severity Filter Level: all | (On SmartVision appliances) Severity levels of SmartVision events for which Trellix event notification are sent. Use the |
Example
The following example displays the status about the customized notification preferences:
hostname # show fenotify preferences Notification customized settings: IPS delivery mode: confirmation HTTP(s) notification using fenet proxy: yes Rsyslog notification Stripping off line feedback: yes Notification timeout: 600 seconds SSL cipher list: compatible SSL minimum protocol version: tls1.2 SIEM Riskware support: no Normalize IPS Event: yes Fetch Original Alert in Notification: no Include OS-Changes in Normal/Extended Alert in Notification: yes Translating Layer Severn Protocol in Alert in Notification: no Notification CPU-Sender Ratio: 4 Maximize resource usage: no Preserve Original Http Header Seperator: no Alert ATI Updates: yes CEF Compliance: yes Mask off http AU elements: yes Smart Vision Event Severity Filter Level: all
User role
Admin or Operator
Command mode
Enable
Supported appliances
This command was introduced before Release 7.5.0.
Network Security:
Release 7.5: Command output enhanced for IPS-enabled Network Security appliances to include IPS delivery mode.
Release 7.7: Command output enhanced to include Advanced Threat Intelligence (ATI) alert updates for notifications through HTTP and email protocols.
Release 7.8: Command output enhanced for Network Security and Central Management System appliances to include notification data format.
Release 7.9.1: Command output enhanced for Network Security and Central Management System appliances to include SIEM riskware support.
Release 8.2: Command output enhanced for SmartVision appliances to include the severity level of SmartVision events for which notifications are sent.
Endpoint Security (HX): Release 3.5