show smartvision status

Prev Next

Displays the status of SmartVision, the context service, and data exfiltration detection on a SmartVision-capable appliance.

On

SmartVision Edition appliances, which are Network Security appliances with SmartVision Edition appliance licenses

, SmartVision features are enabled by default. On SmartVision-capable Network Security sensors and integrated appliances, you must enable SmartVision explicitly.

SmartVision appliances are described in the Network Security SmartVision Feature Guide

.

Note

You can also run this command remotely from the command line of an integrated TrellixCentral Management System appliance using the central management appliance proxying mechanism.

To view SmartVision configuration, data exfiltration detection configuration, and SmartVision rules file version information, use the show smartvision config command instead.

Syntax

show smartvision status

Parameters

None

Output

The following table describes the output fields for the show smartvision status command. Fields are listed in the approximate order in which they appear in the output.

Field

Description

Detection

Whether SmartVision detection is enabled:

  • yes―This is the default status for SmartVision Edition sensors.

  • no―This is the default status for SmartVision-capable Network Security sensors and integrated appliances.

Context service

Whether the context service is enabled:

  • running―The context service is enabled.

  • unmanaged―The context service is not enabled.

Data exfil detection state

Whether data exfiltration detection is enabled:

  • running―Data exfiltration detection is enabled.

  • unmanaged―Data exfiltration detection is not enabled.

DGA detection state

Whether DGA detection is enabled:

  • running―DGA detection is enabled.

  • unmanaged―DGA detection is not enabled.

Beaconing detection state

Whether beaconing detection is enabled:

  • running― beaconing detection is enabled.

  • unmanaged―beaconing detection is not enabled.

TLS detection state

Whether TLS detection is enabled:

  • running―TLS detection is enabled.

  • unmanaged―TLS detection is not enabled.

Event-Based Pcap Capture state

Whether Event-Based Pcap Capture state is enabled:

  • running―Event-Based Pcap Capture state is enabled.

  • unmanaged―Event-Based Pcap Capture state is not enabled.

SmartVision Edition configured

Whether SmartVision Edition is configured:

  • yes―SmartVision Edition is configured.

  • no―SmartVision Edition is not configured.

Note

You can convert the Classic product edition into the SmartVision product edition using the following CLI command, smartvision sv-mode enable. Use the no version of the command to convert it back to Classic edition.

Conversion will require a manual appliance reboot.

Datapath mode reboot required

Whether Datapath mode reboot is required:

  • yes―Datapath mode reboot is required.

  • no―Datapath mode reboot is not required.

Current datapath mode

Current datapath mode:

  • Classic sensor

  • SmartVision-capable sensor

SmartVision Edition supported

Whether the Network Security hardware or virtual appliance is capable of operating as a SmartVision Edition sensor:

  • no―The appliance is not capable of operating as a SmartVision Edition sensor.

  • yes―The appliance is capable of operating as a SmartVision Edition sensor.

SmartVision appliances are described in the Network Security SmartVision Feature Guide

Example

In the following example, SmartVision is not enabled on a Network Security sensor and the sensor does not support SmartVision.

Note

SmartVision-capable Network Security sensors are listed in the Network Security SmartVision Feature Guide.

hostname # show smartvision status 
SmartVision State
        Detection                      : no
        Context Service                : running
        Data exfil detection state     : unmanaged
        Beaconing detection state      : running
        TLS detection state            : running
        Event-Based Pcap Capture state : running
        DGA detection state            : running 
        
        SmartVision Edition configured : no
        Datapath mode reboot required  : no
        Current datapath mode          : Classic Sensor
        SmartVision Edition supported  : no

In the following example, SmartVision is enabled on a Network Security integrated appliance.

Note

SmartVision-capable Network Security integrated appliances are listed in the Network Security SmartVision Feature Guide.

hostname # show smartvision status 
SmartVision State
        Detection                      : yes
        Context Service                : running
        Data exfil detection state     : running
        Beaconing detection state      : running
        TLS detection state            : running
        Event-Based Pcap Capture state : running
        DGA detection state            : running

        SmartVision Edition configured : yes
        Datapath mode reboot required  : yes
        Current datapath mode          : Classic Sensor
        SmartVision Edition supported  : yes

User role

Admin, Analyst, or Operator.

Command mode

Enable

Supported appliances

This command is supported on the following appliances running the specified releases or later:

  • Network Security: Release 8.0