The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Setting up HTTP servers using the CLI

Prev Next

To set up HTTP servers, perform the following subtasks:

  • Add the HTTP servers

  • Configure the HTTP server listing

To add an HTTP server:
  1. Go to CLI configuration mode.

    hostname > enable

    hostname # configure terminal

  2. Enable HTTP notifications:

    hostname (config) # fenotify http enable

  3. Specify the name of the HTTP server (for example, NX7400) to receive the notification. URLs and email addresses are not allowed.

    hostname (config) # fenotify http service <service-name>

  4. Specify which servers will post HTTP notifications (one server per command):

    hostname (config) # fenotify http service <service_name> enable

  5. Specify the URL for each HTTP server to receive the notification:

    hostname (config) # fenotify http service <service_name> server-url <url>

  6. Save the configuration:

    hostname (config) # write memory

To configure the HTTP server listing:
  1. Go to CLI configuration mode:

    hostname > enable

    hostname # configure terminal

  2. Enable HTTP notifications:

    hostname (config) # fenotify http enable

  3. (Optional) If authentication is required for the server, enable authentication and then specify the user name and password for HTTP authentication:

    hostname (config) # fenotify http service <service_name> auth enable

    hostname (config) # fenotify http service <service_name> auth username <user_name>

    hostname (config) # fenotify http service <service_name> auth password <password>

  4. Select the event type:

    hostname (config) # fenotify http alert indicator-presence enable

    hostname (config) # fenotify http alert indicator-executed enable

    hostname (config) # fenotify http alert exploit-detected enable

    hostname (config) # fenotify http alert exploit-blocked enable

    hostname (config) # fenotify http alert malware-object enable

  5. Specify the delivery frequency for HTTP notifications to receive information about each event, sent when the event is triggered. Enter:

    hostname (config) # fenotify http service <service_name> prefer message delivery per-event

  6. (Optional) If you want to use SSL for notifications:

    hostname (config) # fenotify http service <service_name> ssl enable

    hostname (config) # fenotify http service <service_name> ssl verify

  7. Specify the service provider. The default service provider is generic.

    Note

    Trellix recommends using the generic service provider. Endpoint Security (HX) servers do not support Aruba.

    • To select the currently active service provider, enter:

      hostname (config) # fenotify http service <service_name> provider default

    • To select the generic provider, enter:

      hostname (config) # fenotify http service <service_name> provider generic

  8. Specify the format of notifications as JSON Normal. To post notifications in JSON Normal format containing detailed information and abstracts such as alert type, ID, source IP, malware name, hostname, and alert URL without any redundant information, enter:

    hostname (config) # fenotify http service <service_name> provider generic message format json-normal

  9. Save the configuration:

    hostname (config) # write memory