Use the View and add HTTP Servers section on the HTTP tab of the Notification Settings page to add and configure HTTP servers.
.png)
Click the Settings tab.
Click Notifications on the side bar.
Click the HTTP tab and locate the View and add HTTP Servers section.
Click Add HTTP Server. The Add New HTTP Server dialog box opens.
Enter the name of the HTTP server that will post the notification (for example, NX7400 or HX4500) in the Server name box.
Note
Do not enter URLs and email addresses in the Server name box.
Select the Enabled checkbox to choose which servers will post HTTP notifications.
Click Update HTTP Server.
Enter the URL of the server to post the HTTP notification in the Server Url box.
Leave the User box blank. This option will be deprecated.
Select the Alerts Update Notification checkbox to choose which servers will post HTTP notifications when ATI alert updates are detected.
(Optional) If authentication is required for the server, select the Auth checkbox. If you checked the Auth checkbox, you must also enter a username and password.
Enter the user name for HTTP authentication in the Username box.
Enter the password for HTTP authentication in the Password box.
(Optional) If you want to use SSL for notifications, select the SSL Enable checkbox and SSL Verify checkboxes.
Select the event type or All Events in the Events Notification drop-down list box to post HTTP notifications when the specified events are detected.
Note
Selections on the Summary tab take precedence over your selection here. For example, if you globally disable an event type on the Summary tab, no alert notifications will be sent for that event type, regardless of your selection in this drop-down list box.
Select the delivery frequency in the Delivery drop-down list box:
Per Event (recommended)—Send a notification each time an event of this type occurs.
Default—Use the delivery frequency specified in the Default delivery box in the HTTP Settings area.
Daily Digest—Send a daily notification of specified events detected in the past 24 hours in the selected format and level of details (default is Concise).
Select a service provider in the Default provider drop-down list box. The default service provider is Generic.
Note
Trellix recommends using the generic service provider.
Select XML, JSON, or Text as the notification format and select which level of detail is provided in the Message Format drop-down list box. Select Default to use the format specified in the Default format box in the HTTP Settings area.
Normal—This format contains detailed information and abstracts, such as alert type, ID, source IP, malware name, hostname, and alert URL without redundant information.
Concise—This format contains basic information, such as alert type, ID, source IP, malware name, hostname, and alert URL.
Extended—This format contains detailed information and abstracts, including data-theft information (if any) and static-analysis details. This format provides all details about files and objects modified during analysis.
Click Add New HTTP Server.
Click the Settings tab.
Click Notifications on the side bar.
Click the HTTP tab and locate the View and add HTTP Servers section.
Click the HTTP link in the table header.
Click the server in the Name column in the View and add HTTP Servers section.
Click the icon in the Edit column.
Update the settings as needed.
Click the Settings tab.
Click Notifications on the side bar.
Click the HTTP tab and locate the View and add HTTP Servers section.
Select the checkbox next to the server.
Click Enable or Disable.
Click Yes to confirm the action.
Click the Settings tab.
Click Notifications on the side bar.
Click the HTTP tab and locate the View and add HTTP Servers section.
Select the checkbox next to the server.
Click Remove.
Click Yes to confirm the action.