Use the CLI commands in this topic to set up the default configuration for HTTP notifications.
Go to CLI configuration mode:
hostname > enablehostname # configure terminalEnable HTTP notifications:
hostname (config) # fenotify http enableSpecify the default delivery frequency to receive information about each event, sent when the event is triggered. Enter:
hostname (config) # fenotify http default delivery per-eventSpecify the default service provider. The default service provider is
generic.Note
Trellix recommends using the
genericservice provider. Endpoint SecurityEndpoint Security (HX) servers do not support Aruba.To select Aruba as the provider, enter:
hostname (config) # fenotify http default provider arubaTo select the generic provider, enter:
hostname (config) # fenotify http default provider generic
Specify the default format of the notifications as JSON Normal format. To post notifications in JSON Normal format containing detailed information and abstracts such as alert type, ID, source IP, malware name, hostname, and alert URL without any redundant information, enter:
hostname (config) # fenotify http service <service_name> provider generic message format json-normalSave the configuration:
hostname (config) # write memory