Integrating AX appliance with NDR Console for malware analysis
Prev Next To configure NDR for malware analysis on the Malware Analysis Series appliance:
Log in to the NDR as npadmin using the NDR IP address or FQDN. For example:
$ ssh npadmin@10.1.0.1
or
$ ssh npadmin@exampleFQDN
Enter privileged mode:
npadmin@ia> enable
Enter the npadmin password. The password can be 5 to 24 characters long.
[sudo] password for npadmin: <password>
Enter configuration mode:
npadmin@ia# configure system
Enter the file analysis menu:
npadmin@ia# fileanalysis
Select A and enter the AX's IP address or the FQDN.
When using FQDNs for any configuration setting, you must first configure a valid DNS server. See Chapter 4: Network Configuration for more details.
Select U and enter the IA's api_analyst username.
Select P and enter the password for the api_analyst username.
Select L to change the amount of files to send at one time to the AX. The default is 5. The range is 1-10.
Select X to exit.
Was this article helpful?
Related articles
Intrusion Prevention System (IPS) > Network Detection and Response (NDR) > NDR 4.x > Network Detection and Response Product Guide 4.x > Managing alerts
Intrusion Prevention System (IPS) > Network Detection and Response (NDR) > NDR 4.x > Network Detection and Response Product Guide 4.x > Supported Integrations > Integrating with Trellix appliances > Integrating with AX Series appliance for malware analysis
Intrusion Prevention System (IPS) > Network Detection and Response (NDR) > NDR 4.x > Network Detection and Response Product Guide 4.x > Supported Integrations > Integrating with Trellix appliances > Integrating with Trellix PX > Synching PX and NDR metadata through CLI