Follow these steps to view the mapping of network event types to Trellix event notification services using CLI commands.
Prerequisites
Determine whether the appliance is in Helix mode. When a network event is detected by a SmartVision appliance in a Helix environment, the appliance makes the alert information available to Helix.
In this example, the appliamce is deployed in a Helix environment.
hostname # show helix Helix Configurations: Enabled : yes Single Sign-On : allowed Console URL : https://apps.fireeye.com/helix/id/abcdef123 Alert Sync Enabled : yes Alert Sync From : 0 days old Alert Sync Max Count : 10000
To determine which Trellix event notification services are enabled, check the values displayed in the Global row for the four notification protocol columns (email, http, rsyslog, and snmp).
In this example, all of the Trellix event notification services are enabled (set to
yes).
A
novalue in a field means that the notification service is disabled and does not send notifications for any event type.Note
When a network event is detected by a SmartVisionappliance in a Helix environment, the appliance makes the alert information available to Helix.