Viewing notification services enabled for alert types using the CLI

Prev Next

Follow these steps to view the mapping of network event types to Trellix event notification services using CLI commands.

Prerequisites

To view alert distribution settings using the CLI:
  1. Determine whether the appliance is in Helix mode. When a network event is detected by a SmartVision appliance in a Helix environment, the appliance makes the alert information available to Helix.

    In this example, the appliamce is deployed in a Helix environment.

    hostname # show helix
    Helix Configurations:
    Enabled : yes
    Single Sign-On : allowed
    Console URL : https://apps.fireeye.com/helix/id/abcdef123
    Alert Sync Enabled : yes
    Alert Sync From : 0 days old
    Alert Sync Max Count : 10000
  2. To determine which Trellix event notification services are enabled, check the values displayed in the Global row for the four notification protocol columns (email, http, rsyslog, and snmp).

    In this example, all of the Trellix event notification services are enabled (set to yes).

    SmartVision_AlertDistribution_fenotifyMethodsEnabled_120dpi.png

    A no value in a field means that the notification service is disabled and does not send notifications for any event type.

    Note

    When a network event is detected by a SmartVisionappliance in a Helix environment, the appliance makes the alert information available to Helix.