The eAlerts > Alerts page of an Email Security - Server appliance lists malware alerts (MVX-verified malware events) and associated callback activity. The page lists the alerts organized by attack (recipient, sender, and attack rule name). Multiple alerts associated with the same victim and signature rule are combined in a single row, called an alert grouping.
If the appliance has obtained threat intelligence for an alert, a Threat Info badge appears in the Badges column.
Note
For managed Email Security - Server appliances, ATI badges and ATI information are visible from the Central Management System Web UI only.
For more information, see About ATI.
Prerequisites
Log in to the Email Security - Serverappliance Web UI with a user account that is associated with the Analyst, Operator, or Admin role.
Verify that the Email Security - Server appliance is enabled for ATI. Use the show ati status CLI command.
Open the eAlerts > Alerts page.
Choose the ATI alert that you want to view. To locate an alert in the list, you can modify the display in any of the following ways:
Change the time duration displayed in the list.
Sort the list on a column by clicking the column name.
Filter the list on any column by clicking Show/Hide Filters and then entering or selecting the filter match criteria in the text box. You can filter the Badges column for Threat Info badges.
Click the Threat Info badge for the alert you want to view.
In the Email Alerts: Filtered Alerts page, locate the Advanced Threat Intel section. This section displays the threat intelligence for the alert. For a detailed description of the threat intelligence information, see ATI badges in the Web UI.