show smartvision config

Prev Next

Displays SmartVision configuration, data exfiltration detection configuration, and SmartVision rules file version information.

On

SmartVision Edition appliances, which are Network Security appliances with SmartVision Edition appliance licenses

SmartVision features are enabled by default. On SmartVision-capable Network Security sensors and integrated appliances, you must enable SmartVision explicitly.

SmartVision appliances are described in the Network Security SmartVision Feature Guide

.

Note

You can also run this command remotely from the command line of an integrated TrellixCentral Management System appliance using the central management appliance proxying mechanism.

To show only whether SmartVision and data exfiltration detection are running, you can also use the show smartvision status command instead.

Syntax

show smartvision config

Parameters

None

Output

Detection enabled

Whether SmartVision detection is enabled:

  • yes―This is the default status for SmartVision Edition sensors.

  • no―This is the default status for SmartVision-capable Network Security sensors and integrated appliances.

Context service enabled

Whether the context service is enabled:

  • yes―This is the default status for CLI appliances.

  • no―Related Network Activity is not available for CLI alerts.

SC killswitch

Whether the SC kill switch is enabled:

  • yes―This is the default status for SmartVision Edition sensors and SmartVision-capable Network Security sensors and integrated appliances.

  • no―SC killswitch has been explicitly disabled.

Data exfil detection enabled

Whether data exfiltration detection is enabled:

  • yes―This is the default status for SmartVision Edition sensors and SmartVision-capable Network Security sensors and integrated appliances.

  • no―Data exfiltration detection has been explicitly disabled.

Beaconing detection enabled

Whether beaconing detection is enabled:

  • yes―This is the default status for SmartVision Edition sensors and SmartVision-capable Network Security sensors and integrated appliances.

  • no―Beaconing detection has been explicitly disabled.

TLS detection enabled

Whether TLS detection is enabled:

  • yes―This is the default status for SmartVision Edition sensors and SmartVision-capable Network Security sensors and integrated appliances.

  • no―TLS detection has been explicitly disabled.

DGA detection enabled

Whether DGA detection is enabled:

  • yes―This is the default status for SmartVision Edition sensors and SmartVision-capable Network Security sensors and integrated appliances.

  • no―DGA detection has been explicitly disabled.

Packet capture enabled

Whether packet capture is enabled:

  • yes―This is the default status for SmartVision Edition sensors and SmartVision-capable Network Security sensors and integrated appliances.

  • no―Packet capture has been explicitly disabled.

Packet capture backup enabled

Whether packet capture backup is enabled:

  • yes―This is the default status for SmartVision Edition sensors and SmartVision-capable Network Security sensors and integrated appliances.

  • no―Packet capture backup has been explicitly disabled.

Base version

The minimum SmartVision rules file version supported by the SmartVision rules engine.

Rule version

The SmartVision rules file version. When SmartVision alert information is sent to the Helix console, the SmartVision rules file version number is included in the JSON object.

Exfil checkpoint enabled

Whether exfiltration checkpoint is enabled:

  • yes―This is the default status for SmartVision Edition sensors and SmartVision-capable Network Security sensors and integrated appliances.

  • no―Exfiltration checkpoint has been explicitly disabled.

Data exfil detection customer networks

IP address ranges of the destination network hosts to be monitored for data theft activity.

Data exfil detection whitelist networks

The destination IP address ranges for which data exfiltration alerts are not to be generated.

Beaconing detection customer networks

IP address ranges of the destination network hosts to be monitored for beaconing activity.

Beaconing detection whitelist networks

The destination IP address ranges for which beaconing alerts are not to be generated.

DGA detection whitelist domain

The destination IP address ranges for which DGA alerts are not to be generated.

Examples

This example output shows that SmartVision and data exfiltration detection are disabled and their whitelists and the data exfiltration homenet are not configured.

hostname # show smartvision config
					
SmartVision Config

       Detection Enabled             : no
       Context Service enabled       : yes
       SC Killswitch                 : no
       Data exfil detection enabled  : no
       Beaconing detection enabled   : no
       TLS detection enabled         : no
       DGA detection enabled         : yes        
       Packet capture enabled        : no        
       Packet capture backup enabled : yes
       Base version                  : 2
       Rule version                  : 3

       Data exfil detection customer networks:
               None configured

       Data exfil detection whitelist networks:
               None configured

       Beaconing detection whitelist networks:
               None configured

This example shows that SmartVision and data exfiltration detection are enabled. The three SmartVision and data exfiltration detection whitelists are configured, and appliance is configured to detect data exfiltration activity on the 192.168.0.0/24 network..

hostname # show smartvision config

SmartVision Config

       Detection Enabled             : yes
       Context Service enabled       : yes
       SC Killswitch                 : no
       Data exfil detection enabled  : yes
       Beaconing detection enabled   : no
       TLS detection enabled         : no
       Base version                  : 2
       Rule version                  : 3

       Data exfil detection customer networks:
               None configured

       Data exfil detection whitelist networks:
               192.168.0.0/24

       Beaconing detection whitelist networks:
               None configured

User role

Admin, Analyst, or Operator.

Command mode

Enable

Supported appliances

This command is supported on the following appliances running the specified releases or later:

  • Network Security: Release 8.0