Use the show commbroker health command to monitor the following health states of the Communications Broker Sender (Comm Broker):
Not Authenticated—The Comm Broker is in the process of authenticating with Helix and the client certificate has been received from the server.
Authenticated—The Comm Broker has been authenticated with Helix and is in the process of connecting to the VPC within an AWS endpoint.
Connected—The Comm Broker is connected to the VPC within an AWS endpoint and is sending the network event logs. The Comm Broker also contains an active Process Identification Number (PID) and a client certificate.
Authentication Failure—The Comm Broker failed to authenticate with Helix because either communication failed or the client certificate expired.
Failure—The Comm Broker failed to connect to the VPC within an AWS endpoint.
Use the show commbroker stats command to view the statistics about the frequency of syslog and JSON event logs that are generated by the Network Security appliance and sent to Helix. Both the syslog and JSON event logs report the number of events per second (EPS). EPS is part of event logging that is used to monitor and record every instance of events that are generated by the Network Security appliance.
For details about these commands, see the CLI Command Reference.
Prerequisites
Administrator or Operator access to the Network Security appliance
A connection to the Dynamic Threat Intelligence (DTI) Cloud
An active subscription to Helix
Configure a valid hostname for the VPC within an AWS endpoint.
Enable the Comm Broker.
Go to CLI enable mode.
hostname > enable
View the health status of the Comm Broker.
hostname # show commbroker health
Go to CLI enable mode.
hostname > enable
Network Security
hostname # show commbroker stats INPUT STATS ----------- Total Syslog Events Received : 11 Syslog Average EPS Rate : 0 Total Json Events Received : 0 Json Average EPS Rate : 0 OUTPUT STATS ------------ Total Syslog Events sent : 11 Total Json and L7-Meta-data Events sent : 179