Checking system health and status

Prev Next

You can use the Web UI or CLI to view health and status information.

Prerequisites
  • Monitor, Operator, Analyst, or Admin access

Checking system health using the Central Management System Web UI

Use the Health Check page to check appliance health and status.

Note

This illustration is from a Network Security appliance, but is representative of NX appliances as well.

Note

See Deployment verification for details about the information that is displayed when you click Deployment Check at the top of this page.

NX_HealthCheck_scap.png
CM_SystemInfo_scap.png
To view health and status:
  1. Click the About tab of Central Management System Web UI.

  2. Click Health Check.

    The results of the last check are displayed.

  3. Review the system information.

  4. To update the results, click Refresh Health Check.

The following sections contain descriptions of the information in each area of the page.

Version information

The About > Health Check > Version Information section provides an up-to-date view of the software running on your appliance and compares that with the available software on the Trellix DTI network.

Note

Information about the IPMI version is not displayed for a user that is assigned an Analyst role.

All_HealthCheck_VersionInfo_scap.png

Information

Description

Software Version

Compares the software version running on the system to the available software on the DTI network. If a newer version exists, administrators are prompted to upgrade the software.

Installed Version

Displays the current software version running on the system.

Available Version

Displays the current software version available on the DTI network.

Content Version

Compares the security content version on the appliance to the available version on the DTI network and displays the status and the version that is currently installed. If a newer version exists, or if an error condition exists, administrators are prompted to take appropriate action.

Last Updated At

Shows the last time the security content was updated.

IPMI Version

Compares the IPMI firmware version running on the system to the available version on the DTI network. If a newer version exists, administrators are prompted to upgrade the firmware.

Installed Version

Displays the current IPMI firmware version.

Available Version

Displays the latest available IPMI firmware version.

Guest images information

The About > Health Check > Guest Images Information section provides an up-to-date view of the guest images installed on your appliance.

All_HealthCheck_GuestImagesInfo_scap.png

Information

Description

Profiles

Compares the profile versions within your installed guest image and compares them profiles to the latest profiles available on the DTI network. If newer profiles are available, administrators are prompted to update their guest images.

Profile Versions

For each profile found in the current guest image, the profile version number is displayed.

System information

The About > Health Check > System Information status section provides an up-to-date status of your appliance hardware and alerts administrators when problems are found.

All_HealthCheck_SystemInfo_scap.png

Information

Description

Product Info

Status of whether the appliance is operating normally. If a problem is found in system hardware performance, the administrator is alerted.

Model

The hardware model.

Name

The product name.

Type

The product type.

License

Displays whether the software license has been successfully installed.

Processing Load

Provides analysis of the overall load the system is carrying. If it is nearing capacity, the administrator is alerted.

Average Load

The average processing load handled by the system.

Elapsed

The current uptime of the system in days, hours, minutes, and seconds.

Detection Engine

Displays the status of the detection engine. If the Detection Engine is not running, the administrator is alerted.

VM Analyzing

The number of virtual machines currently analyzing suspect content.

VM Allowed

The maximum number of VMs that can run concurrently to analyze suspect content.

Hardware

The About > Health Check > Hardware section provides status on the appliance’s hardware components.

Note

Information about the disk, RAID, and chassis are not displayed for a user that is assigned an Analyst role.

All_HealthCheck_Hardware_scap.png

Information

Description

Disk

Displays whether the hard disk is online. If a problem is found, the administrator is alerted.

Device State

Displays the current state of the hard disk.

Device Support

Displays the type of device available on the system.

Self Assessment

Indicates whether the disk passed its internal self-tests.

User Capacity

Shows the disk capacity on the disk.

Chassis

Displays status of the hardware chassis. If a problem is found, the administrator is alerted.

Lock

Provides the state of the chassis lock.

Boot Up State

Provides the boot up status.

Power Supply State

Provides the state of the power supply.

RAID

Provides the status of RAID.

Dynamic threat intelligence DTI cloud

The About > Health Check > DTI Cloud section displays the status of the connection between the appliance and the DTI network.

This example is from a Network Security appliance, but is representative of other Trellix appliances as well.

All_HealthCheck_DTICloud_scap.png

Information

Description

DTI Client

Shows whether the DTI client is running on the system.

Username

Displays the current user of the system.

Support Updates

Displays the status of the support license.

Security Content

Displays whether security content sharing is enabled on the system.

Sharing

Displays the type of content update license purchased.

Content Updates

Displays the status of the content update license.

Download

Compares the source for software updates such as system images, guest images, and security content to the available download source on the DTI network and displays the status.

Upload

Compares the destination that is used for software uploads to the available upload destination on the DTI network and displays the status.

Last Communication Time

Shows the last time software updates were downloaded and uploaded.

Features

The About > Health Check > Features section displays the status of the features on the appliance.

Note

This example is from a Network Security appliance, but is representative of other Trellix appliances as well.

NX_HealthCheck_Features_scap.png

Information

Description

IPS

Shows whether Integrated Intrusion Prevention System (IPS) features are enabled on the Network Security appliance.

ATI

Shows whether the Advanced Threat Intelligence (ATI) feature is enabled. When you enable the ATI feature, information about MVX-verfied events is provided on the Network Security appliances.

Riskware

Shows whether the riskware detection feature is enabled. When you enable the riskware detection feature, you can distinguish between malicious files and riskware on the Network Security appliance.

TapSender

Shows whether the Evidence Collector module is enabled. When you enable the Evidence Collector module, the appliance sends the network event logs to Trellix Threat Analytics Platform (TAP) in the AWS endpoint that you specified for further analysis.

SmartVision

Shows whether SmartVision is active on the appliance. SmartVision can detect the lateral movement of malware. A SmartVision appliance is any one of the following:

  • SmartVision Edition sensor

  • SmartVision-enabled Network Security sensor

  • SmartVision-enabled Network Security integrated appliance

Custom IOC

Shows whether a Central Management System appliance is enabled to receive indicators of compromise (IOCs) from a third-party feed and distribute them to all managed Network Security appliances or a specific managed Network Security appliance.

Interfaces

The About > Health Check > Interfaces section displays information about each available Ethernet port on the Network Security appliance.

Note

The About > Health Check > Interfaces section is not displayed for a user that is assigned an Analyst role.

All_HealthCheck_Interfaces_scap.png

Information

Description

Interface

Whether the Ethernet port is up or down.

Auto Negotiation

Whether auto negotiation is enabled.

Duplex

The type of duplex communication used by the Ethernet port.

Link Detected

Whether the Ethernet port is currently linked to another port.

Link Transceiver

The location of the link transceiver used to generate Ethernet traffic.

Link Speed

The maximum data speed available on the Ethernet port.

MAC Address

The MAC address of the Ethernet port.

RX Packet

The number of packets received by the Ethernet port during the life of this connection.

TX Packet

The number of packets transmitted by the Ethernet port during the life of this connection.

TX Packets Dropped

The number of packets that were dropped through Ethernet traffic.

Checking system health using the CLI

Use the CLI commands in this topic to view health and status information about Network Security appliance components. This topic describes selected commands that return system, hardware status, DTI network, and interface information. For a full list of commands and details about their usage and parameters, see the CLI Command Reference.

  • Monitor, Operator, or Admin access

  • Admin access for the show ipmi command

Note

The examples in this section are from a Network Security appliance, but they are representative of Trellix appliances as well.

To check appliance health:
  1. Go to CLI enable mode:

    hostname > enable
  2. Display detailed information about the system and the software running on it.

    hostname # show version
    Product name:      Web MPS [licensed]
    Product model:     FireEyeNX9450
    Product edition:   Classic
    Bandwidth:         2000 Mb
    Product release:   wMPS (wMPS) 7.7.0.433916
    Build ID:          #433916
    Build date:        2015-12-29 17:21:57
    Build arch:        x86_64
    Built by:          root@vta114
    Version summary:   wmps wMPS (wMPS) 7.7.0.433916 
    #433916 2015-12-29 17:21:57 x86_64 build@vta108:FireEye (xxx)
    Content Version:   385.314
    Appliance ID:      XXXXXXXXXXXX
    Product model:     FireEyeNX9450
    Host ID:           XXXXXXXXXXX
    System serial num: XXXXXXXXXX
    System UUID:       XXXXXXXX-XXXX-XXXX-XXXX-XXXXXXXXXXXX
    Uptime:            3d 6h 34m 34.205s
    CPU load averages: 0.36 / 0.40 / .38
    Number of CPUs:    32
    System memory:     9210 MB used / 119984 MB free / 129194 MB total
    Swap:              0 MB used / 65536 MB free / 65536 MB total
  3. Display the IPMI configuration:

    hostname # show ipmi
    IPMI LAN Settings
    ----------------------------------------
    Admin Shut Down         : no
    Shut Down               : no
    IP Address Source       : Static Address
    IP Address              : 192.168.42.27
    Subnet Mask             : 0
    Default Gateway IP      : 0
    IPMI Firmware Installed
    -------------------------------
    Firmware Version:         2.67
    Device:                   1
    IPMI Version:             2.0
    IPMI Firmware Available For Update
    -----------------------------------
    New Firmware Version:     2.67
    New Firmware Filename:    FireEye_V267.bin
    Firmware Update Notice:   Firmware is up to date for this release
    
    IPMI Firmware Availability Notice is enabled 
  4. Display overall system status:

    hostname * show system health
    Overall system feature status: Good
  5. Display current status of system and available services:

    hostname # show show health all
    Health Status:
    Last Updated at: : 2019-11-06T20:31:00
    Service:        : System CPU/Memory/Disk IO Health
    Health Status:  : Healthy
    Details:        : Healthy
    Service:        : Global Cache
    Health Status:  : Healthy
    Details:        : Healthy
  6. Display information about the Dynamic Threat Intelligence (DTI) network:

    hostname # show fenet status
    Dynamic Threat Intelligence Service:
        Update source   : <online>
        Enabled         : yes  
        Download        : DTIUser@cloud.fireeye.com  
        Upload          : DTIUser@up-cloud.fireeye.com
        Mil             : DTIUser@mil-cloud.fireeye.com
    
      HTTP Proxy:
         Address        :
         Username       : 
         User-agent     :
    
    Request Session:
         Timeout        : 30   
         Retries        : 3
         Speed Time     : 60
         Max Time       : 14400
         Rate Limit     :
    
         Speed Limit    : 1
      
    Dynamic Threat Intelligence Lockdown:
    Enabled             : no
    Locked              : no
    Lock After          : 5 failed attempts
    
     UPDATES
                        Enabled   Notify  Scheduled   Last Updated At
                        -------   ------  ---------   -------------------
     Security contents: yes       no      every       2016/07/18 19:28:00
     Stats contents:    yes               none        2016/07/18 15:55:00
    
  7. Display status and traffic statistics for all interfaces:

    hostname # show interfaces
    Interface ether1 status:
       Comment:
       Admin up:           yes
       Link up:            yes
       DHCP running:       no
       IP address:         172.00.00.00   
       Netmask:            255.000.0.0
       IPV6 enabled:       no
       Speed:              1000Mb/s (auto)   
       Duplex:             full (auto)
       Interface type:     ethernet
       Interface ifindex:  12  
       Interface source:   physical
       MTU:                1500
       HW address:         00:25:90:D0:A3:76
      RX bytes:        3114981133   TX bytes:       227921679
       RX packets:       31934013     TX packets:     367951
       RX mcast packets: 31564        TX discards:    0
       RX discards:      296          TX errors:      0
       RX errors:        1            TX overruns:    0 
       RX overruns:      0            TX carrier:     0
       RX frame:         0            TX collisions:  0   
                                      TX queue len:   1000
    
    Interface ether2 status:
       Comment:
       Admin up:           yes
       Link up:            no
       DHCP running:       no
       IP address:            
       Netmask:
       IPV6 enabled:       no            
       Speed:              UNKNOWN   
       Duplex:             UNKNOWN
       Interface type:     ethernet
       MTU:                1500
       HW address:         00:25:90:D0:A3:77
    
       RX bytes:           0              TX bytes:       0
       RX packets:         0              TX packets:     0
       RX mcast packets:   0              TX discards:    0
       RX discards:        0              TX errors:      0
       RX errors:          0              TX overruns:    0
       RX overruns:        0              TX carrier:     0
       RX frame:           0              TX collisions:  0   
                                          TX queue len:   0
    
    Interface pether2 status:
       Comment:
       Admin up:           yes
       Link up:            no
       DHCP running:       no
       IP address:
       Netmask:
       IPV6 enabled:       no
       Speed:              UNKNOWN
       Duplex:             UNKNOWN
       Interface type:     ethernet
       Interface ifindex:  9
       Interface source:   physical
       Bridge group:       ether2
       MTU:                1500
       HW address:         00:25:90:D0:A3:77 
      
       RX bytes:           0            TX bytes:       0
       RX packets:         0            TX packets:     0
       RX mcast packets:   0            TX discards:    0
       RX discards:        0            TX errors:      0
       RX errors:          0            TX overruns:    0
       RX overruns:        0            TX carrier:     0
       RX frame:           0            TX collisions:  0   
                                        TX queue len:   1000
    Interface pether3 status:
       Comment:
       Admin up:           yes
       Link up:            yes
       DHCP running:       no
       IP address:         127.0.0.10
       Netmask:            255.255.255.0
       IPV6 enabled:       no
       Speed:              1000 MB/s (auto)
       Duplex:             full (auto)
       Interface type:     ethernet
       Interface ifindex:  6
       Interface source:   physical
       MTU:                1500
       HW address:         00:25:90:D0:A3:67
       
       RX bytes:           31628620500   TX bytes:       0
       RX packets:         46795         TX packets:     0
       RX mcast packets:   367056        TX discards:    0
       RX discards:        212322        TX errors:      0
       RX errors:          0             TX overruns:    0
       RX overruns:        0             TX carrier:     0
       RX frame:           0             TX collisions:  0   
    				     TX queue len:   1000