This command shows whether data streaming of alerts is enabled globally, whether specific alert data streaming types are enabled, and whether OS changes are included in alerts. Global data streaming and the inclusion of OS changes are enabled by default when Trellix Helix mode is enabled on an appliance.
To check data streaming status:
Go to CLI enable mode:
hostname > enable
Check the status:
hostname # show datastreaming helix
Example
hostname # show datastreaming helix Helix Data-streaming configuration: Helix data-streaming enabled : yes Metadata streaming configurations: submission-metadata : yes appliance-stats : yes localsig-metadata : yes Helix Integration Notification Settings: =============================================== enable : yes path : ingest/alert Helix Full URL : https://:443/ingest/alert include os-changes : yes =============================================== alerts status: malware object : yes malware callback : yes web infection : yes infection match : yes domain match : yes IPS event : yes riskware object : yes riskware callback : yes riskware infection : yes smartvision : yes