show fenotify preferences

Prev Next

Displays customized preferences for Trellix event notifications.

This command also displays information about IPS event notification delivery mode, delivery option for HTTP or HTTPS notifications, a delivery option for Rsyslog notifications.

Note

You can also run this command remotely from the command line of an integrated Trellix Central Management System appliance using the Central Management System appliance proxying mechanism.

Syntax

show fenotify preferences

Parameters

None

Output fields

The following table describes the output fields for the show fenotify preferences command. Fields are listed in the approximate order in which they appear in the output.

Field Name

Description

IPS delivery mode

Delivery mode for IPS event notifications:

  • instant—Send only when an IPS event is detected. This is the default value.

  • confirmation—Send only when an attack has been confirmed (either positive or negative).

  • dual—Send both when an IPS event is detected and when an attack has been confirmed.

HTTP(s) notification using fenet proxy

Delivery mode for event messages posted to Web servers using HTTP or HTTPS:

  • yes—System sends HTTP or HTTPS event notifications using an FENET proxy.

  • no—System does not send HTTP or HTTPS event notifications using an FENET proxy.

You can use the following CLI commands to configure the system to pst event messages to Web servers using HTTP or HTTPS: fenet proxy auth, fenet proxy host, and fenet proxy user‑agent. For more information, see the Network Security IPS Feature Guide.

Rsyslog notification Stripping off line feedback

Delivery option to strip off line feedback for event notifications sent to a remote syslog server:

  • yes—System strips off line feedback. This is the default mode.

  • no—System does not strip off line feedback.

You can use the following CLI commands to configure the system to send event notifications to a remote syslog server: fenotify rsyslog default, fenotify rsyslog enable, and fenotify rsyslog service. For more information, see the Network Security IPS Feature Guide.

SIEM Riskware support

Notification option:

  • yes—You receive riskware-callback and riskware-object notifications.

  • no—You do not receive riskware-callback and riskware-object notifications.

Normalize IPS Event

Notification data format:

  • yes—Alert notifications use src/smac/sport for the network traffic source and use dst/dmac/dport as the network traffic destination.

  • no—Alert notifications use src/smac/sport as the network traffic destination (victim) and use dst/dmac/dport as the network traffic source (attacker).

Notification CPU-Sender Ratio

Use the fenotify preferences sender-cpu-ratio CLI command to configure the notification CPU-sender ratio. The range of values is 1 to 1024. When the ratio is set to 1, the performance is highest, but more resources are used. When the ratio is set to 1024, the performance is lowest, but less resources are used.

Smart Vision Event Severity Filter Level: all

(On SmartVision appliances) Severity levels of SmartVision events for which Trellix event notification are sent.

Use the fenotify preferences smartvision-event severity CLI command to configure this setting.

Example

The following example displays the status about the customized notification preferences:

hostname # show fenotify preferences
Notification customized settings:
IPS delivery mode: confirmation
HTTP(s) notification using fenet proxy: yes
Rsyslog notification Stripping off line feedback: yes
Notification timeout: 600 seconds
SSL cipher list: compatible
SSL minimum protocol version: tls1.2
SIEM Riskware support: no
Normalize IPS Event: yes
Fetch Original Alert in Notification: no
Include OS-Changes in Normal/Extended Alert in Notification: yes
Translating Layer Severn Protocol in Alert in Notification: no
Notification CPU-Sender Ratio: 4
Maximize resource usage: no
Preserve Original Http Header Seperator: no
Alert ATI Updates: yes
CEF Compliance: yes
Mask off http AU elements: yes
Smart Vision Event Severity Filter Level: all

User role

Admin or Operator

Command mode

Enable

Supported appliances

This command was introduced before Release 7.5.0.

  • Network Security:

    Release 7.5: Command output enhanced for IPS-enabled Network Security appliances to include IPS delivery mode.

    Release 7.7: Command output enhanced to include Advanced Threat Intelligence (ATI) alert updates for notifications through HTTP and email protocols.

    Release 7.8: Command output enhanced for Network Security and Central Management System appliances to include notification data format.

    Release 7.9.1: Command output enhanced for Network Security and Central Management System appliances to include SIEM riskware support.

    Release 8.2: Command output enhanced for SmartVision appliances to include the severity level of SmartVision events for which notifications are sent.

  • Endpoint Security (HX): Release 3.5