To set up HTTP servers, perform the following subtasks:
Add the HTTP servers
Configure the HTTP server listing
Go to CLI configuration mode.
hostname > enablehostname # configure terminalEnable HTTP notifications:
hostname (config) # fenotify http enableSpecify the name of the HTTP server (for example, NX7400) to receive the notification. URLs and email addresses are not allowed.
hostname (config) # fenotify http service <service-name>Specify which servers will post HTTP notifications (one server per command):
hostname (config) # fenotify http service <service_name> enableSpecify the URL for each HTTP server to receive the notification:
hostname (config) # fenotify http service <service_name> server-url <url>Save the configuration:
hostname (config) # write memory
Go to CLI configuration mode:
hostname > enablehostname # configure terminalEnable HTTP notifications:
hostname (config) # fenotify http enable(Optional) If authentication is required for the server, enable authentication and then specify the user name and password for HTTP authentication:
hostname (config) # fenotify http service <service_name> auth enablehostname (config) # fenotify http service <service_name> auth username <user_name>hostname (config) # fenotify http service <service_name> auth password <password>Select the event type:
hostname (config) # fenotify http alert indicator-presence enablehostname (config) # fenotify http alert indicator-executed enablehostname (config) # fenotify http alert exploit-detected enablehostname (config) # fenotify http alert exploit-blocked enablehostname (config) # fenotify http alert malware-object enableSpecify the delivery frequency for HTTP notifications to receive information about each event, sent when the event is triggered. Enter:
hostname (config) # fenotify http service <service_name> prefer message delivery per-event(Optional) If you want to use SSL for notifications:
hostname (config) # fenotify http service <service_name> ssl enablehostname (config) # fenotify http service <service_name> ssl verifySpecify the service provider. The default service provider is
generic.Note
Trellix recommends using the
genericservice provider. Endpoint Security (HX) servers do not support Aruba.To select the currently active service provider, enter:
hostname (config) # fenotify http service <service_name> provider defaultTo select the generic provider, enter:
hostname (config) # fenotify http service <service_name> provider generic
Specify the format of notifications as JSON Normal. To post notifications in JSON Normal format containing detailed information and abstracts such as alert type, ID, source IP, malware name, hostname, and alert URL without any redundant information, enter:
hostname (config) # fenotify http service <service_name> provider generic message format json-normalSave the configuration:
hostname (config) # write memory