The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Setting up HTTP servers

Prev Next

To set up HTTP servers, perform the following subtasks:

  • Add the HTTP servers

  • Configure the HTTP server listing

To add an HTTP server:
  1. Enable the CLI configuration mode:

    hostname > enable
    hostname # configure terminal
  2. Enable HTTP notifications:

    hostname (config) # fenotify http enable
  3. Specify the name of the HTTP server to receive the notification. URLs and email addresses are not allowed.

    hostname (config) # fenotify http service service-name
  4. Specify which servers will post HTTP notifications (one server per command):

    hostname (config) # fenotify http service service_name enable
  5. Specify the URL for each HTTP server to receive the notification:

    hostname (config) # fenotify http service service_name server-url url
  6. Save the configuration:

    hostname (config) # write memory
To configure the HTTP server listing:
  1. Enable the CLI configuration mode:

    hostname > enablehostname # configure terminal
  2. Enable HTTP notifications:

    hostname (config) # fenotify http enable
  3. (Optional) If authentication is required for the server, enable authentication and then specify the user name and password for HTTP authentication:

    hostname (config) # fenotify http service service_name auth enable
    hostname (config) # fenotify http service service_name auth username user_name
    • To obfuscate the password as you type it:

      hostname (config) # fenotify http service service_name auth password
      Password: <******>
      Confirm: <******>
    • To skip the prompt and display the password in clear text:

      hostname (config) # fenotify http service service_name auth password password
  4. Specify the delivery schedule for HTTP notifications:

    Note

    Trellix recommends using per-event notifications.

    • To send a daily notification of all malware objects detected the past 24 hours in the selected format and level of details (default is Concise), enter:

      hostname (config) # fenotify http service service_name prefer message delivery daily-digest
    • To send a notification each time a malware object is detected, enter:

      hostname (config) # fenotify http service service_name prefer message delivery per-event
  5. (Optional) If you want to use SSL for notifications:

    hostname (config) # fenotify http service service_name ssl enable
    hostname (config) # fenotify http service service_name ssl verify
  6. Specify the service provider. The default service provider is generic.

    Note

    Trellix recommends using the generic service provider.

    • To select the currently active service provider, enter:

      hostname (config) # fenotify http service service_name provider default
    • To select the generic provider, enter:

      hostname (config) # fenotify http service service_name provider generic
    • To select Aruba as the provider, enter:

      hostname (config) # fenotify http service service_name provider aruba
  7. Select one of the XML, JavaScript Object Notation (JSON), or Text options for the format of the HTTP notifications:

    Note

    The json_legacy-concise, json_legacy-extended, and json_legacy-normal formats are deprecated.

    • To post notifications in XML Concise format containing basic information such as alert type, ID, source IP, malware name, hostname, and alert URL, enter:

      hostname (config) # fenotify http service service_name provider generic message format xml-concise
    • To post notifications in XML Extended format containing detailed information and abstracts including data-theft information (if any) and static-analysis details (XML Extended provides all details about files and objects modified during analysis.), enter:

      hostname (config) # fenotify http service service_name provider generic message format xml-extended
    • To post notifications in XML Normal format containing detailed information and abstracts such as alert type, ID, source IP, malware name, hostname, and alert URL without any redundant information, enter:

      hostname (config) # fenotify http service service_name provider generic message format xml-normal
    • To post notifications in JSON Concise format containing basic information such as alert type, ID, source IP, malware name, hostname, and alert URL, enter:

      hostname (config) # fenotify http service service_name provider generic message format  json-concise
    • To post notifications in JSON Extended format containing detailed information and abstracts including data-theft information (if any) and static-analysis details (JSON Extended provides all details about files and objects modified during analysis.), enter:

      hostname (config) # fenotify http service service_name provider generic message format json-extended
    • To post notifications in JSON Normal format containing detailed information and abstracts such as alert type, ID, source IP, malware name, hostname, and alert URL without any redundant information, enter:

      hostname (config) # fenotify http service service_name provider generic message format json-normal
    • To post notifications in Text Concise format containing basic information such as alert type, ID, source IP, malware name, hostname, and alert URL, enter:

      hostname (config) # fenotify http service service_name provider generic message format text-concise
    • To post notifications in Text Extended format containing detailed information and abstracts including data-theft information (if any) and static-analysis details (Text Extended provides all details about files and objects modified during analysis.), enter:

      hostname (config) # fenotify http service service_name provider generic message format text-extended
    • To post notifications in Text Normal format containing detailed information and abstracts such as alert type, ID, source IP, malware name, hostname, and alert URL without any redundant information, enter:

      hostname (config) # fenotify http service service_name provider generic message format text-normal
  8. Save the configuration:

    hostname (config) # write memory