show alerts type <type> detail list [timeframe <timeframe>]

Prev Next

Displays a list of alerts of the specified type.

Syntax

show alerts type <malware_type> detail list [timeframe <timeframe>]

Parameters

malware_type

Shows alerts for the specified alert type. Not all alert types are available on all appliances.

  • all—All alert types

  • malware-callback—Malware-callback alerts

  • domain-match—Domain-match alerts

  • infection-match—Infection-match alerts

  • web-infection—Web-infection alerts

  • malware-object—Malware-object alerts

timeframe

Shows alerts in the specified time range:

  • past-hour—Past hour

  • past-day—Past day

  • past-week—Past week

  • past-2weeks—Past two weeks

  • past-month—Past month

  • past-3months—Past three months

  • from—Displays alerts for a time range in the format <yyyy/mm/dd> <hh:mm:ss> to <yyyy/mm/dd> <hh:mm:ss>

Example

The following command displays a list of malware-object alerts:

hostname # show alerts type malware-object detail list timeframe from 
2019/03/15 09:00:00 to 2019/03/15 09:30:00
majr MO 55224    2019-03-15 09:02:04+00 Trojan.Dridex 
        a@a.com->b@test.com
majr MO 55225    2019-03-15 09:02:04+00 Trojan.Dridex
        a@a.com->b@test.com
majr MO 55226    2019-03-15 09:09:40+00 Trojan.Upatre
        a@a.com->b@test.com
majr MO 55227    2019-03-15 09:09:40+00 Trojan.Upatre
        a@a.com->b@test.com
majr MO 55228    2019-03-15 09:14:41+00 Worm.Andromeda
        a@a.com->b@test.com
majr MO 55229    2019-03-15 09:14:41+00 Worm.Andromeda
        a@a.com->b@test.com
majr MO 55230    2019-03-15 09:17:06+00 Trojan.Dridex
        a@a.com->b@test.com
majr MO 55231    2019-03-15 09:17:06+00 Trojan.Dridex
        a@a.com->b@test.com
majr MO 55232    2019-03-15 09:22:00+00 Trojan.EXE.FEBeta
        a@a.com->b@test.com
majr MO 55234    2019-03-15 09:27:06+00 Trojan.Dridex
        a@a.com->b@test.com
majr MO 55235    2019-03-15 09:27:06+00 Trojan.Dridex
        a@a.com->b@test.com

Output fields

The following table describes each field in the output:

Field

Description

severity

Severity of the alert

type

Alert type

ID

Alert ID

time

Time of the alert

name

Malware name

source

The smtp-mail-from address.

destination

The smtp-to address.

User role

Admin, Monitor, Operator

Command mode

Enable

Supported appliances

This command is supported on the following appliances running the specified releases or later:

  • Malware Analysis: Before release 6.4

  • Central Management System: Before release 6.4

  • Email Security — Server: Before release 6.4

  • File Protect: Before release 6.4

  • Network Security: Before release 6.4