To set up HTTP servers, perform the following subtasks:
Add the HTTP servers
Configure the HTTP server listing
Go to CLI configuration mode.
hostname > enablehostname # configure terminalEnable HTTP notifications:
hostname (config) # fenotify http enableSpecify the name of the HTTP server (for example, NX7400) to receive the notification. URLs and email addresses are not allowed.
hostname (config) # fenotify http service <service-name>Specify which servers will post HTTP notifications (one server per command):
hostname (config) # fenotify http service <service_name> enableSpecify the URL for each HTTP server to receive the notification:
hostname (config) # fenotify http service <service_name> server-url <url>Save the configuration:
hostname (config) # write memory
Go to CLI configuration mode:
hostname > enablehostname # configure terminalEnable HTTP notifications:
hostname (config) # fenotify http enable(Optional) If authentication is required for the server, enable authentication and then specify the user name and password for HTTP authentication:
hostname (config) # fenotify http service <service_name> auth enablehostname (config) # fenotify http service <service_name> auth username <user_name>hostname (config) # fenotify http service <service_name> auth password <password>Select the event type:
hostname (config) # fenotify http alert domain-match enablehostname (config) # fenotify http alert infection-match enablehostname (config) # fenotify http alert ips-event enablehostname (config) # fenotify http alert malware-callback enablehostname (config) # fenotify http alert malware-object enablehostname (config) # fenotify http alert web-infection enableEnable the specified servers to post HTTP notifications when ATI alert updates are detected (one server per command):
hostname (config) # fenotify http service <service_name> alerts-update enableSpecify the delivery frequency for HTTP notifications:
Note
Trellix recommends using
per-eventnotifications.To receive information about all events detected in the past 24 hours, enter:
hostname (config) # fenotify http service <service_name> prefer message delivery daily-digestTo receive a daily notification for each entity that was the source of the event, enter:
hostname (config) # fenotify http service service_name prefer message delivery daily-per-sourceTo receive an hourly notification for each entity that was the source of the event, enter:
hostname (config) # fenotify http service <service_name> prefer message delivery hourly-per-sourceTo receive a notification every minute for each entity that was the source of the event, enter:
hostname (config) # fenotify http service <service_name> prefer message delivery per-1min-per-sourceTo receive a notification every 5 minutes for each entity that was the source of the event, enter:
hostname (config) # fenotify http service <service_name> prefer message delivery per-5min-per-sourceTo receive information about each event, sent when the event is triggered, enter:
hostname (config) # fenotify http service <service_name> prefer message delivery per-event
(Optional) If you want to use SSL for notifications:
hostname (config) # fenotify http service <service_name> ssl enablehostname (config) # fenotify http service <service_name> ssl verifySpecify the service provider. The default service provider is
generic.Note
Trellix recommends using the
genericservice provider.To select the currently active service provider, enter:
hostname (config) # fenotify http service <service_name> provider defaultTo select the generic provider, enter:
hostname (config) # fenotify http service <service_name> provider genericTo select Aruba as the provider, enter:
hostname (config) # fenotify http service <service_name> provider aruba
Select one of the XML, JavaScript Object Notation (JSON), or Text options for the format of the HTTP notifications:
Note
The json_legacy-concise, json_legacy-extended, and json_legacy-normal formats are deprecated.
To post notifications in XML Concise format containing basic information such as alert type, ID, source IP, malware name, hostname, and alert URL, enter:
hostname (config) # fenotify http service <service_name> provider generic message format xml-conciseTo post notifications in XML Extended format containing detailed information and abstracts including data-theft information (if any) and static-analysis details (XML Extended provides all details about files and objects modified during analysis.), enter:
hostname (config) # fenotify http service <service_name> provider generic message format xml-extendedTo post notifications in XML Normal format containing detailed information and abstracts such as alert type, ID, source IP, malware name, hostname, and alert URL without any redundant information, enter:
hostname (config) # fenotify http service <service_name> provider generic message format xml-normal
To post notifications in JSON Concise format containing basic information such as alert type, ID, source IP, malware name, hostname, and alert URL, enter:
hostname (config) # fenotify http service <service_name> provider generic message format json-conciseTo post notifications in JSON Extended format containing detailed information and abstracts including data-theft information (if any) and static-analysis details (JSON Extended provides all details about files and objects modified during analysis.), enter:
hostname (config) # fenotify http service <service_name> provider generic message format json-extendedTo post notifications in JSON Normal format containing detailed information and abstracts such as alert type, ID, source IP, malware name, hostname, and alert URL without any redundant information, enter:
hostname (config) # fenotify http service <service_name> provider generic message format json-normalTo post notifications in Text Concise format containing basic information such as alert type, ID, source IP, malware name, hostname, and alert URL, enter:
hostname (config) # fenotify http service <service_name> provider generic message format text-conciseTo post notifications in Text Extended format containing detailed information and abstracts including data-theft information (if any) and static-analysis details (Text Extended provides all details about files and objects modified during analysis.), enter:
hostname (config) # fenotify http service <service_name> provider generic message format text-extended
To post notifications in Text Normal format containing detailed information and abstracts such as alert type, ID, source IP, malware name, hostname, and alert URL without any redundant information, enter:
hostname (config) # fenotify http service <service_name> provider generic message format text-normal
Save the configuration:
hostname (config) # write memory