Log in to the NDR as npadmin using the NDR IP address or FQDN. For example:
$ ssh npadmin@10.1.0.1or
$ ssh npadmin@exampleFQDNEnter privileged mode:
npadmin@ia> enableEnter the npadmin password. The password can be 5 to 24 characters long.
[sudo] password for npadmin: <password>Enter configuration mode:
npadmin@ia# configure systemThe prompt changes to
npadmin@hostname(config)#on the terminal indicating that configuration mode is enabled. You can now proceed with the configurating metadata.Enter the metadata configuration and then press
Enter.npadmin@ia# metadataTo enable import of metadata from PX, type
Tin theEnter your choice fieldand pressEnter.Type
A, pressEnterto add a PX appliance.Type the IP address of PX and then press Enter.
The appliance displays the key fingerprint and asks you if you want to continue using key. Press Y.
Enter the username used in PX and then press Enter.
Enter the password used to connect to PX, Press Enter.
Keep the default option unchanged in the Customize source directory on PX[data], press Enter.
The following metadata engines are displayed one after the other. The engines are disabled by default and shows
Y/Nto reflect the disabled status. Type Y for each engine to enable them. You can choose to enable any detection engine as per your investigation requirement.Enable beaconing engine (disabled) : Y/N - Press
Yto enable beaconing engine.Enable data-exfill engine (disabled) : Y/N - Press
Yto enable data exfiltration engine.
Type
Sto save the configuration. The PX appliance is added to NDR and is displayed in the Connected PXes row.
Configuring PX metadata using CLI
- Published on Sep 4, 2026
- 1 minute(s) read
Was this article helpful?