Fume configuration enables you to control layer-7 metadata protocol events that are generated from the Network Content Processing Engine (Foxd). This data provides rich protocol activity context for alerts and is also streamed to Helix as part of the Evidence Collector feature.
Additionally, you can enable Malware Object Analysis and generate layer-7 metadata events for the WebSocket protocol.
To configure FUME:
Log in to the appliance Web UI.
Click the Settings tab.
Click Fume on the sidebar.
To enable or disable layer-7 metadata event generation for the listed protocols, select or deselect the protocols.
To enable Malware Object Analysis and generate layer-7 metadata events for the WebSocket protocol, select WEBSOCKET OBJECT EXTRACTION.
To enable the detection of malware objects for HTTP post uploads, select OUTBOUND SCANNING.
By default, OUTBOUND SCANNING is not selected.
Click Update.