You can use the Web UI or CLI to view health and status information.
Monitor, Operator, Analyst, or Admin access
Checking system health using the Central Management System Web UI
Use the Health Check page to check appliance health and status.
Note
This illustration is from a Network Security appliance, but is representative of NX appliances as well.
Note
See Deployment verification for details about the information that is displayed when you click Deployment Check at the top of this page.
.png)
.png)
Click the About tab of Central Management System Web UI.
Click Health Check.
The results of the last check are displayed.
Review the system information.
To update the results, click Refresh Health Check.
The following sections contain descriptions of the information in each area of the page.
Version information
The About > Health Check > Version Information section provides an up-to-date view of the software running on your appliance and compares that with the available software on the Trellix DTI network.
Note
Information about the IPMI version is not displayed for a user that is assigned an Analyst role.
.png)
Information | Description |
|---|---|
Software Version | Compares the software version running on the system to the available software on the DTI network. If a newer version exists, administrators are prompted to upgrade the software. |
Installed Version | Displays the current software version running on the system. |
Available Version | Displays the current software version available on the DTI network. |
Content Version | Compares the security content version on the appliance to the available version on the DTI network and displays the status and the version that is currently installed. If a newer version exists, or if an error condition exists, administrators are prompted to take appropriate action. |
Last Updated At | Shows the last time the security content was updated. |
IPMI Version | Compares the IPMI firmware version running on the system to the available version on the DTI network. If a newer version exists, administrators are prompted to upgrade the firmware. |
Installed Version | Displays the current IPMI firmware version. |
Available Version | Displays the latest available IPMI firmware version. |
Guest images information
The About > Health Check > Guest Images Information section provides an up-to-date view of the guest images installed on your appliance.
.png)
Information | Description |
|---|---|
Profiles | Compares the profile versions within your installed guest image and compares them profiles to the latest profiles available on the DTI network. If newer profiles are available, administrators are prompted to update their guest images. |
Profile Versions | For each profile found in the current guest image, the profile version number is displayed. |
System information
The About > Health Check > System Information status section provides an up-to-date status of your appliance hardware and alerts administrators when problems are found.
.png)
Information | Description |
|---|---|
Product Info | Status of whether the appliance is operating normally. If a problem is found in system hardware performance, the administrator is alerted. |
Model | The hardware model. |
Name | The product name. |
Type | The product type. |
License | Displays whether the software license has been successfully installed. |
Processing Load | Provides analysis of the overall load the system is carrying. If it is nearing capacity, the administrator is alerted. |
Average Load | The average processing load handled by the system. |
Elapsed | The current uptime of the system in days, hours, minutes, and seconds. |
Detection Engine | Displays the status of the detection engine. If the Detection Engine is not running, the administrator is alerted. |
VM Analyzing | The number of virtual machines currently analyzing suspect content. |
VM Allowed | The maximum number of VMs that can run concurrently to analyze suspect content. |
Hardware
The About > Health Check > Hardware section provides status on the appliance’s hardware components.
Note
Information about the disk, RAID, and chassis are not displayed for a user that is assigned an Analyst role.
.png)
Information | Description |
|---|---|
Disk | Displays whether the hard disk is online. If a problem is found, the administrator is alerted. |
Device State | Displays the current state of the hard disk. |
Device Support | Displays the type of device available on the system. |
Self Assessment | Indicates whether the disk passed its internal self-tests. |
User Capacity | Shows the disk capacity on the disk. |
Chassis | Displays status of the hardware chassis. If a problem is found, the administrator is alerted. |
Lock | Provides the state of the chassis lock. |
Boot Up State | Provides the boot up status. |
Power Supply State | Provides the state of the power supply. |
RAID | Provides the status of RAID. |
Dynamic threat intelligence DTI cloud
The About > Health Check > DTI Cloud section displays the status of the connection between the appliance and the DTI network.
This example is from a Network Security appliance, but is representative of other Trellix appliances as well.
.png)
Information | Description |
|---|---|
DTI Client | Shows whether the DTI client is running on the system. |
Username | Displays the current user of the system. |
Support Updates | Displays the status of the support license. |
Security Content | Displays whether security content sharing is enabled on the system. |
Sharing | Displays the type of content update license purchased. |
Content Updates | Displays the status of the content update license. |
Download | Compares the source for software updates such as system images, guest images, and security content to the available download source on the DTI network and displays the status. |
Upload | Compares the destination that is used for software uploads to the available upload destination on the DTI network and displays the status. |
Last Communication Time | Shows the last time software updates were downloaded and uploaded. |
Features
The About > Health Check > Features section displays the status of the features on the appliance.
Note
This example is from a Network Security appliance, but is representative of other Trellix appliances as well.
.png)
Information | Description |
|---|---|
IPS | Shows whether Integrated Intrusion Prevention System (IPS) features are enabled on the Network Security appliance. |
ATI | Shows whether the Advanced Threat Intelligence (ATI) feature is enabled. When you enable the ATI feature, information about MVX-verfied events is provided on the Network Security appliances. |
Riskware | Shows whether the riskware detection feature is enabled. When you enable the riskware detection feature, you can distinguish between malicious files and riskware on the Network Security appliance. |
TapSender | Shows whether the Evidence Collector module is enabled. When you enable the Evidence Collector module, the appliance sends the network event logs to Trellix Threat Analytics Platform (TAP) in the AWS endpoint that you specified for further analysis. |
SmartVision | Shows whether SmartVision is active on the appliance. SmartVision can detect the lateral movement of malware. A SmartVision appliance is any one of the following:
|
Custom IOC | Shows whether a Central Management System appliance is enabled to receive indicators of compromise (IOCs) from a third-party feed and distribute them to all managed Network Security appliances or a specific managed Network Security appliance. |
Interfaces
The About > Health Check > Interfaces section displays information about each available Ethernet port on the Network Security appliance.
Note
The About > Health Check > Interfaces section is not displayed for a user that is assigned an Analyst role.
.png)
Information | Description |
|---|---|
Interface | Whether the Ethernet port is up or down. |
Auto Negotiation | Whether auto negotiation is enabled. |
Duplex | The type of duplex communication used by the Ethernet port. |
Link Detected | Whether the Ethernet port is currently linked to another port. |
Link Transceiver | The location of the link transceiver used to generate Ethernet traffic. |
Link Speed | The maximum data speed available on the Ethernet port. |
MAC Address | The MAC address of the Ethernet port. |
RX Packet | The number of packets received by the Ethernet port during the life of this connection. |
TX Packet | The number of packets transmitted by the Ethernet port during the life of this connection. |
TX Packets Dropped | The number of packets that were dropped through Ethernet traffic. |
Checking system health using the CLI
Use the CLI commands in this topic to view health and status information about Network Security appliance components. This topic describes selected commands that return system, hardware status, DTI network, and interface information. For a full list of commands and details about their usage and parameters, see the CLI Command Reference.
Monitor, Operator, or Admin access
Admin access for the
show ipmicommand
Note
The examples in this section are from a Network Security appliance, but they are representative of Trellix appliances as well.
Go to CLI enable mode:
hostname > enable
Display detailed information about the system and the software running on it.
hostname # show version Product name: Web MPS [licensed] Product model: FireEyeNX9450 Product edition: Classic Bandwidth: 2000 Mb Product release: wMPS (wMPS) 7.7.0.433916 Build ID: #433916 Build date: 2015-12-29 17:21:57 Build arch: x86_64 Built by: root@vta114 Version summary: wmps wMPS (wMPS) 7.7.0.433916 #433916 2015-12-29 17:21:57 x86_64 build@vta108:FireEye (xxx) Content Version: 385.314 Appliance ID: XXXXXXXXXXXX
Product model: FireEyeNX9450 Host ID: XXXXXXXXXXX System serial num: XXXXXXXXXX System UUID: XXXXXXXX-XXXX-XXXX-XXXX-XXXXXXXXXXXX
Uptime: 3d 6h 34m 34.205s CPU load averages: 0.36 / 0.40 / .38 Number of CPUs: 32 System memory: 9210 MB used / 119984 MB free / 129194 MB total Swap: 0 MB used / 65536 MB free / 65536 MB total
Display the IPMI configuration:
hostname # show ipmi IPMI LAN Settings ---------------------------------------- Admin Shut Down : no Shut Down : no IP Address Source : Static Address IP Address : 192.168.42.27 Subnet Mask : 0 Default Gateway IP : 0
IPMI Firmware Installed ------------------------------- Firmware Version: 2.67 Device: 1 IPMI Version: 2.0
IPMI Firmware Available For Update ----------------------------------- New Firmware Version: 2.67 New Firmware Filename: FireEye_V267.bin Firmware Update Notice: Firmware is up to date for this release IPMI Firmware Availability Notice is enabled
Display overall system status:
hostname * show system health Overall system feature status: Good
Display current status of system and available services:
hostname # show show health all
Health Status:
Last Updated at: : 2019-11-06T20:31:00
Service: : System CPU/Memory/Disk IO Health
Health Status: : Healthy
Details: : Healthy
Service: : Global Cache
Health Status: : Healthy
Details: : Healthy
Display information about the Dynamic Threat Intelligence (DTI) network:
hostname # show fenet status
Dynamic Threat Intelligence Service:
Update source : <online> Enabled : yes Download : DTIUser@cloud.fireeye.com Upload : DTIUser@up-cloud.fireeye.com Mil : DTIUser@mil-cloud.fireeye.com HTTP Proxy:
Address : Username : User-agent :
Request Session:
Timeout : 30 Retries : 3 Speed Time : 60 Max Time : 14400 Rate Limit : Speed Limit : 1 Dynamic Threat Intelligence Lockdown:
Enabled : no Locked : no Lock After : 5 failed attempts
UPDATES Enabled Notify Scheduled Last Updated At ------- ------ --------- ------------------- Security contents: yes no every 2016/07/18 19:28:00 Stats contents: yes none 2016/07/18 15:55:00
Display status and traffic statistics for all interfaces:
hostname # show interfaces
Interface ether1 status: Comment: Admin up: yes Link up: yes DHCP running: no IP address: 172.00.00.00 Netmask: 255.000.0.0 IPV6 enabled: no Speed: 1000Mb/s (auto) Duplex: full (auto) Interface type: ethernet Interface ifindex: 12 Interface source: physical MTU: 1500 HW address: 00:25:90:D0:A3:76
RX bytes: 3114981133 TX bytes: 227921679 RX packets: 31934013 TX packets: 367951 RX mcast packets: 31564 TX discards: 0 RX discards: 296 TX errors: 0 RX errors: 1 TX overruns: 0 RX overruns: 0 TX carrier: 0 RX frame: 0 TX collisions: 0 TX queue len: 1000
Interface ether2 status: Comment: Admin up: yes Link up: no DHCP running: no IP address: Netmask: IPV6 enabled: no Speed: UNKNOWN Duplex: UNKNOWN Interface type: ethernet MTU: 1500 HW address: 00:25:90:D0:A3:77 RX bytes: 0 TX bytes: 0 RX packets: 0 TX packets: 0 RX mcast packets: 0 TX discards: 0 RX discards: 0 TX errors: 0 RX errors: 0 TX overruns: 0 RX overruns: 0 TX carrier: 0 RX frame: 0 TX collisions: 0 TX queue len: 0
Interface pether2 status: Comment: Admin up: yes Link up: no DHCP running: no IP address: Netmask: IPV6 enabled: no Speed: UNKNOWN Duplex: UNKNOWN Interface type: ethernet Interface ifindex: 9 Interface source: physical Bridge group: ether2 MTU: 1500 HW address: 00:25:90:D0:A3:77 RX bytes: 0 TX bytes: 0 RX packets: 0 TX packets: 0 RX mcast packets: 0 TX discards: 0 RX discards: 0 TX errors: 0 RX errors: 0 TX overruns: 0 RX overruns: 0 TX carrier: 0 RX frame: 0 TX collisions: 0 TX queue len: 1000
Interface pether3 status: Comment: Admin up: yes Link up: yes DHCP running: no IP address: 127.0.0.10 Netmask: 255.255.255.0 IPV6 enabled: no Speed: 1000 MB/s (auto) Duplex: full (auto) Interface type: ethernet Interface ifindex: 6 Interface source: physical MTU: 1500 HW address: 00:25:90:D0:A3:67 RX bytes: 31628620500 TX bytes: 0 RX packets: 46795 TX packets: 0 RX mcast packets: 367056 TX discards: 0 RX discards: 212322 TX errors: 0 RX errors: 0 TX overruns: 0 RX overruns: 0 TX carrier: 0 RX frame: 0 TX collisions: 0 TX queue len: 1000