To configure the SMTP settings, perform the following subtasks:
Specify the SMTP server
Set the default SMTP notification settings
Enable the CLI configuration mode:
hostname > enablehostname # configure terminalEnable email notifications:
hostname (config) # fenotify email enableSet the mail relay address used to send the email notifications:
hostname (config) # fenotify email mailhub address ip_addressSet the mail port used to send the email notifications.
hostname (config) # fenotify email mailhub port port-numberSave the configuration:
hostname (config) # write memory
Enable the CLI configuration mode:
hostname > enablehostname # configure terminalEnable email notifications:
hostname (config) # fenotify email enableSet the domain from which emails appear to come:
hostname (config) # fenotify email domain email-domain(Optional) To include the hostname in the return address for email notifications:
hostname (config) # fenotify email return host-name host_nameSet the user name in the return address for email notifications (the default is
do-not-reply):hostname (config) # fenotify email return user-name user_nameSelect one of the XML, JavaScript Object Notation (JSON), or Text options for the default format of the notification:
Note
The json_legacy-concise, json_legacy-extended, and json_legacy-normal formats are deprecated.
To send notifications in XML Concise format containing basic information such as alert type, ID, source IP, malware name, hostname, and alert URL, enter:
hostname (config) # fenotify email default format xml-conciseTo send notifications in XML Extended format containing detailed information and abstracts including data-theft information (if any) and static-analysis details (XML Extended provides all details about files and objects modified during analysis.), enter:
hostname (config) # fenotify email default format xml-extended
To send notifications in XML Normal format containing detailed information and abstracts such as alert type, ID, source IP, malware name, hostname, and alert URL without any redundant information, enter:
hostname (config) # fenotify email default format xml-normalTo send notifications in JSON Concise format containing basic information such as alert type, ID, source IP, malware name, hostname, and alert URL, enter:
hostname (config) # fenotify email default format json-conciseTo send notifications in JSON Extended format containing detailed information and abstracts including data-theft information (if any) and static-analysis details (JSON Extended provides all details about files and objects modified during analysis.), enter:
hostname (config) # fenotify email default format json-extended
To send notifications in JSON Normal format containing detailed information and abstracts such as alert type, ID, source IP, malware name, hostname, and alert URL without any redundant information, enter:
hostname (config) # fenotify email default format json-normalTo send notifications in Text Concise format containing basic information such as alert type, ID, source IP, malware name, hostname, and alert URL, enter:
hostname (config) # fenotify email default format text-conciseTo send notifications in Text Extended format containing detailed information and abstracts including data-theft information (if any) and static-analysis details (Text Extended provides all details about files and objects modified during analysis.), enter:
hostname (config) # fenotify email default format text-extended
To send notifications in Text Normal format containing detailed information and abstracts such as alert type, ID, source IP, malware name, hostname, and alert URL without any redundant information, enter:
hostname (config) # fenotify email default format text-normal
Specify how the notification is delivered by default:
To deliver the notification as an email attachment, enter:
hostname (config) # notify email default send-as attachment
To deliver the notification in the email body (the default), enter:
hostname (config) # notify email default send-as in-line
Specify the default delivery schedule for email notifications:
Note
Trellix recommends using
per-eventnotifications.To receive information about all events detected in the past 24 hours, enter:
hostname (config) # notify email default delivery daily-digest
To receive information about each event, sent when the event is triggered, enter:
hostname (config) # notify email default delivery per-event
Save the configuration:
hostname (config) # write memory