show smartvision config

Prev Next

The show smartvision config command shows the configuration settings for and data exfiltration detection and the current and minimum supported versions of the rules file.

Note

Although this command shows information about and data exfiltration detection, the two features are enabled and disabled independently from one another.

The show smartvision config command output consists of the following fields:

Detection Enabled

Whether detection is enabled:

  • yes―This is the default status for Edition appliances.

  • no―This is the default status for -capable Network Security sensors and integrated appliances.

Context Service enabled

Whether the context service is enabled:

  • yes―This is the default status for appliances.

  • no―Related Network Activity is not available for alerts.

SC Killswitch

Whether XXXXXXXXXXXXXXXXXXXXXXXXXXX:

  • yes―XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXx.

  • no―XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXx.

Data exfil detection enabled

Whether data exfiltration detection is enabled:

  • yes―This is the default status for Edition appliances and SmartVision-capable Network Security sensors and integrated appliances.

  • no―Data exfiltration detection has been explicitly disabled.

Beaconing detection enabled

Whether XXXXXXXXXXXXXXXXXXXXXXXXXXX:

  • yes―XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXx.

  • no―XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXx.

TLS detection enabled

Whether XXXXXXXXXXXXXXXXXXXXXXXXXXX:

  • yes―XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXx.

  • no―XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXx.

Base version

The minimum rules file version supported by the rules engine.

Rule version

The rules file version. When alert information is sent to Helix, the rules file version number is included in the JSON object.

Data exfil detection customer networks

IP address ranges of the internal network hosts to be monitored for data theft activity.

Data exfil detection whitelist networks

The destination IP address ranges for which data exfiltration alerts are not to be generated.

Beaconing detection whitelist networks

IP address ranges of the internal network hosts to be excluded from XXXXXXXXXXXX.