Displays SmartVision configuration, data exfiltration detection configuration, and SmartVision rules file version information.
On
SmartVision Edition appliances, which are Network Security appliances with SmartVision Edition appliance licenses
SmartVision features are enabled by default. On SmartVision-capable Network Security sensors and integrated appliances, you must enable SmartVision explicitly.
SmartVision appliances are described in the Network Security SmartVision Feature Guide
.
Note
You can also run this command remotely from the command line of an integrated TrellixCentral Management System appliance using the central management appliance proxying mechanism.
To show only whether SmartVision and data exfiltration detection are running, you can also use the show smartvision status command instead.
Syntax
show smartvision config
Parameters
None
Output
Detection enabled
Whether SmartVision detection is enabled:
yes―This is the default status for SmartVision Edition sensors.no―This is the default status for SmartVision-capable Network Security sensors and integrated appliances.
Context service enabled
Whether the context service is enabled:
yes―This is the default status for CLI appliances.no―Related Network Activity is not available for CLI alerts.
SC killswitch
Whether the SC kill switch is enabled:
yes―This is the default status for SmartVision Edition sensors and SmartVision-capable Network Security sensors and integrated appliances.no―SC killswitch has been explicitly disabled.
Data exfil detection enabled
Whether data exfiltration detection is enabled:
yes―This is the default status for SmartVision Edition sensors and SmartVision-capable Network Security sensors and integrated appliances.no―Data exfiltration detection has been explicitly disabled.
Beaconing detection enabled
Whether beaconing detection is enabled:
yes―This is the default status for SmartVision Edition sensors and SmartVision-capable Network Security sensors and integrated appliances.no―Beaconing detection has been explicitly disabled.
TLS detection enabled
Whether TLS detection is enabled:
yes―This is the default status for SmartVision Edition sensors and SmartVision-capable Network Security sensors and integrated appliances.no―TLS detection has been explicitly disabled.
DGA detection enabled
Whether DGA detection is enabled:
yes―This is the default status for SmartVision Edition sensors and SmartVision-capable Network Security sensors and integrated appliances.no―DGA detection has been explicitly disabled.
Packet capture enabled
Whether packet capture is enabled:
yes―This is the default status for SmartVision Edition sensors and SmartVision-capable Network Security sensors and integrated appliances.no―Packet capture has been explicitly disabled.
Packet capture backup enabled
Whether packet capture backup is enabled:
yes―This is the default status for SmartVision Edition sensors and SmartVision-capable Network Security sensors and integrated appliances.no―Packet capture backup has been explicitly disabled.
Base version
The minimum SmartVision rules file version supported by the SmartVision rules engine.
Rule version
The SmartVision rules file version. When SmartVision alert information is sent to the Helix console, the SmartVision rules file version number is included in the JSON object.
Exfil checkpoint enabled
Whether exfiltration checkpoint is enabled:
yes―This is the default status for SmartVision Edition sensors and SmartVision-capable Network Security sensors and integrated appliances.no―Exfiltration checkpoint has been explicitly disabled.
Data exfil detection customer networks
IP address ranges of the destination network hosts to be monitored for data theft activity.
Data exfil detection whitelist networks
The destination IP address ranges for which data exfiltration alerts are not to be generated.
Beaconing detection customer networks
IP address ranges of the destination network hosts to be monitored for beaconing activity.
Beaconing detection whitelist networks
The destination IP address ranges for which beaconing alerts are not to be generated.
DGA detection whitelist domain
The destination IP address ranges for which DGA alerts are not to be generated.
Examples
This example output shows that SmartVision and data exfiltration detection are disabled and their whitelists and the data exfiltration homenet are not configured.
hostname # show smartvision config SmartVision Config Detection Enabled : no Context Service enabled : yes SC Killswitch : no Data exfil detection enabled : no Beaconing detection enabled : no TLS detection enabled : no DGA detection enabled : yes Packet capture enabled : no Packet capture backup enabled : yes Base version : 2 Rule version : 3 Data exfil detection customer networks: None configured Data exfil detection whitelist networks: None configured Beaconing detection whitelist networks: None configured
This example shows that SmartVision and data exfiltration detection are enabled. The three SmartVision and data exfiltration detection whitelists are configured, and appliance is configured to detect data exfiltration activity on the 192.168.0.0/24 network..
hostname # show smartvision config SmartVision Config Detection Enabled : yes Context Service enabled : yes SC Killswitch : no Data exfil detection enabled : yes Beaconing detection enabled : no TLS detection enabled : no Base version : 2 Rule version : 3 Data exfil detection customer networks: None configured Data exfil detection whitelist networks: 192.168.0.0/24 Beaconing detection whitelist networks: None configured
User role
Admin, Analyst, or Operator.
Command mode
Enable
Supported appliances
This command is supported on the following appliances running the specified releases or later:
Network Security: Release 8.0