Checking system health using the CLI

Prev Next

Use the CLI commands in this topic to view health and status information about Malware Analysis appliance components. This topic describes selected commands that return system, hardware status, DTI network, and interface information. For a full list of commands and details about their usage and parameters, see the CLI Command Reference.

  • Monitor, Operator, or Admin access

  • Admin access for the show ipmi command

Note

The examples in this section are from a Network Security appliance, but they are representative of Trellix appliances as well.

To check appliance health:
  1. Go to CLI enable mode:

    hostname > enable
  2. Display detailed information about the system and the software running on it.

    hostname # show version
    Product name:      Web MPS [licensed]
    Product model:     FireEyeNX9450
    Product edition:   Classic
    Bandwidth:         2000 Mb
    Product release:   wMPS (wMPS) 7.7.0.433916
    Build ID:          #433916
    Build date:        2015-12-29 17:21:57
    Build arch:        x86_64
    Built by:          root@vta114
    Version summary:   wmps wMPS (wMPS) 7.7.0.433916 
    #433916 2015-12-29 17:21:57 x86_64 build@vta108:FireEye (xxx)
    Content Version:   385.314
    Appliance ID:      XXXXXXXXXXXX
    Product model:     FireEyeNX9450
    Host ID:           XXXXXXXXXXX
    System serial num: XXXXXXXXXX
    System UUID:       XXXXXXXX-XXXX-XXXX-XXXX-XXXXXXXXXXXX
    Uptime:            3d 6h 34m 34.205s
    CPU load averages: 0.36 / 0.40 / .38
    Number of CPUs:    32
    System memory:     9210 MB used / 119984 MB free / 129194 MB total
    Swap:              0 MB used / 65536 MB free / 65536 MB total
  3. Display the IPMI configuration:

    hostname # show ipmi
    IPMI LAN Settings
    ----------------------------------------
    Admin Shut Down         : no
    Shut Down               : no
    IP Address Source       : Static Address
    IP Address              : 192.168.42.27
    Subnet Mask             : 0
    Default Gateway IP      : 0
    IPMI Firmware Installed
    -------------------------------
    Firmware Version:         2.67
    Device:                   1
    IPMI Version:             2.0
    IPMI Firmware Available For Update
    -----------------------------------
    New Firmware Version:     2.67
    New Firmware Filename:    FireEye_V267.bin
    Firmware Update Notice:   Firmware is up to date for this release
    
    IPMI Firmware Availability Notice is enabled 
  4. Display overall system status:

    hostname * show system health
    Overall system feature status: Good
  5. Display current status of system and available services:

    hostname # show show health all
    Health Status:
    Last Updated at: : 2019-11-06T20:31:00
    Service:        : System CPU/Memory/Disk IO Health
    Health Status:  : Healthy
    Details:        : Healthy
    Service:        : Global Cache
    Health Status:  : Healthy
    Details:        : Healthy
  6. Display information about the Dynamic Threat Intelligence (DTI) network:

    hostname # show fenet status
    Dynamic Threat Intelligence Service:
        Update source   : <online>
        Enabled         : yes  
        Download        : DTIUser@cloud.fireeye.com  
        Upload          : DTIUser@up-cloud.fireeye.com
        Mil             : DTIUser@mil-cloud.fireeye.com
    
      HTTP Proxy:
         Address        :
         Username       : 
         User-agent     :
    
    Request Session:
         Timeout        : 30   
         Retries        : 3
         Speed Time     : 60
         Max Time       : 14400
         Rate Limit     :
    
         Speed Limit    : 1
      
    Dynamic Threat Intelligence Lockdown:
    Enabled             : no
    Locked              : no
    Lock After          : 5 failed attempts
    
     UPDATES
                        Enabled   Notify  Scheduled   Last Updated At
                        -------   ------  ---------   -------------------
     Security contents: yes       no      every       2016/07/18 19:28:00
     Stats contents:    yes               none        2016/07/18 15:55:00
    
  7. Display status and traffic statistics for all interfaces:

    hostname # show interfaces
    Interface ether1 status:
       Comment:
       Admin up:           yes
       Link up:            yes
       DHCP running:       no
       IP address:         172.00.00.00   
       Netmask:            255.000.0.0
       IPV6 enabled:       no
       Speed:              1000Mb/s (auto)   
       Duplex:             full (auto)
       Interface type:     ethernet
       Interface ifindex:  12  
       Interface source:   physical
       MTU:                1500
       HW address:         00:25:90:D0:A3:76
      RX bytes:        3114981133   TX bytes:       227921679
       RX packets:       31934013     TX packets:     367951
       RX mcast packets: 31564        TX discards:    0
       RX discards:      296          TX errors:      0
       RX errors:        1            TX overruns:    0 
       RX overruns:      0            TX carrier:     0
       RX frame:         0            TX collisions:  0   
                                      TX queue len:   1000
    
    Interface ether2 status:
       Comment:
       Admin up:           yes
       Link up:            no
       DHCP running:       no
       IP address:            
       Netmask:
       IPV6 enabled:       no            
       Speed:              UNKNOWN   
       Duplex:             UNKNOWN
       Interface type:     ethernet
       MTU:                1500
       HW address:         00:25:90:D0:A3:77
    
       RX bytes:           0              TX bytes:       0
       RX packets:         0              TX packets:     0
       RX mcast packets:   0              TX discards:    0
       RX discards:        0              TX errors:      0
       RX errors:          0              TX overruns:    0
       RX overruns:        0              TX carrier:     0
       RX frame:           0              TX collisions:  0   
                                          TX queue len:   0
    
    Interface pether2 status:
       Comment:
       Admin up:           yes
       Link up:            no
       DHCP running:       no
       IP address:
       Netmask:
       IPV6 enabled:       no
       Speed:              UNKNOWN
       Duplex:             UNKNOWN
       Interface type:     ethernet
       Interface ifindex:  9
       Interface source:   physical
       Bridge group:       ether2
       MTU:                1500
       HW address:         00:25:90:D0:A3:77 
      
       RX bytes:           0            TX bytes:       0
       RX packets:         0            TX packets:     0
       RX mcast packets:   0            TX discards:    0
       RX discards:        0            TX errors:      0
       RX errors:          0            TX overruns:    0
       RX overruns:        0            TX carrier:     0
       RX frame:           0            TX collisions:  0   
                                        TX queue len:   1000
    Interface pether3 status:
       Comment:
       Admin up:           yes
       Link up:            yes
       DHCP running:       no
       IP address:         127.0.0.10
       Netmask:            255.255.255.0
       IPV6 enabled:       no
       Speed:              1000 MB/s (auto)
       Duplex:             full (auto)
       Interface type:     ethernet
       Interface ifindex:  6
       Interface source:   physical
       MTU:                1500
       HW address:         00:25:90:D0:A3:67
       
       RX bytes:           31628620500   TX bytes:       0
       RX packets:         46795         TX packets:     0
       RX mcast packets:   367056        TX discards:    0
       RX discards:        212322        TX errors:      0
       RX errors:          0             TX overruns:    0
       RX overruns:        0             TX carrier:     0
       RX frame:           0             TX collisions:  0   
    				     TX queue len:   1000