The show smartvision config command shows the configuration settings for and data exfiltration detection and the current and minimum supported versions of the rules file.
Note
Although this command shows information about and data exfiltration detection, the two features are enabled and disabled independently from one another.
The show smartvision config command output consists of the following fields:
Detection Enabled
Whether detection is enabled:
yes―This is the default status for Edition appliances.no―This is the default status for -capable Network Security sensors and integrated appliances.
Context Service enabled
Whether the context service is enabled:
yes―This is the default status for appliances.no―Related Network Activity is not available for alerts.
SC Killswitch
Whether XXXXXXXXXXXXXXXXXXXXXXXXXXX:
yes―XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXx.no―XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXx.
Data exfil detection enabled
Whether data exfiltration detection is enabled:
yes―This is the default status for Edition appliances and SmartVision-capable Network Security sensors and integrated appliances.no―Data exfiltration detection has been explicitly disabled.
Beaconing detection enabled
Whether XXXXXXXXXXXXXXXXXXXXXXXXXXX:
yes―XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXx.no―XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXx.
TLS detection enabled
Whether XXXXXXXXXXXXXXXXXXXXXXXXXXX:
yes―XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXx.no―XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXx.
Base version
The minimum rules file version supported by the rules engine.
Rule version
The rules file version. When alert information is sent to Helix, the rules file version number is included in the JSON object.
Data exfil detection customer networks
IP address ranges of the internal network hosts to be monitored for data theft activity.
Data exfil detection whitelist networks
The destination IP address ranges for which data exfiltration alerts are not to be generated.
Beaconing detection whitelist networks
IP address ranges of the internal network hosts to be excluded from XXXXXXXXXXXX.