This command displays NI feature status (enabled or disabled) and the communication status between Trellix NI and Trellix IPS solution. It also shows other configuration details related to NI integration, such as NI appliance IP address, port, Client Group name, and NI config polling duration as set in the Client Group. Additionally, it displays NI L7 metadata configuration status (enabled or disabled), and the protocols for which it is enabled.
Note
Currently, IPS Sensors export L7 metadata related to HTTP, HTTPS, HTTP2, SMTP, FTP, DNS, SMB, and DCERPC protocols to NI. For SMB and DCERPC protocols, Sensors running on version 11.1 Update 8 or later, and integrated with Trellix NI, send only SmartVision attack-related L7 metadata to NI. See Harnessing SmartVision attacks for effective threat detection and response for more information.
Syntax:
show ni status
Sample Output:
IntruDbg#> show ni status
NI Feature Status : ENABLED
NI IP Address : 10.1.1.1
NI IP Port : 443
NI Group Name : IPSSantaClara
NI Communication Status : UP
NI Config Poll timer : 30:00 minutes
NI Metadata Config : ENABLED
NI Protocols Enabled : HTTP
Applicable to:
NS-series and Virtual IPS Sensors