Marks "standby" malware-object events from file submissions as "active" on the peer appliance in a Network Security pair.
In an Network Security High Availability (HA) deployment, you can manually mark standby malware-object events from file submissions for a specified time period "active" on the peer appliance. This is useful when one of the appliances in the HA pair fails and is removed from the Central Management System appliance. The alerts that were aggregated to the Central Management System appliance and attributed to the failed appliance remain on the Central Management System appliance, but you will be unable to expand the alerts attributed to the failed appliance or submit them to a managed Malware Analysis appliance for deeper forensic analysis. After you mark the events "active" on the peer appliance, they are aggregated to the Central Management System appliance again, but this time they are attributed to the peer appliance. This results in duplicate alerts on the Central Management System appliance, but the alert details and the ability to submit to the Malware Analysis appliance are restored.
Syntax
object-analysis salvage from "<YYYY/MM/DD HH:MM:SS>"
Parameters
YYYY/MM/DD HH:MM:SS
The date and time from which to start marking events as "active." This string must be enclosed in double quotation marks.
Example
The following example salvages the malware-objects from file submissions from 12:00 noon on January 25, 2016.
hostname (config) # object-analysis salvage from "2016/01/25 12:00:00" Total objects salvaged: 25
User role
Admin
Command mode
Config
Supported appliances
This command is supported on the following appliances running the specified releases or later:
Network Security: Release 7.8.0