Displays the cumulative statistics such as the total number of suspicious attachments that were submitted to the virtual machine for analysis, the total number of attachments that were detected as malicious, the total number of events that were detected, and the total number of attachments with each system status type.
By default, the Email Security — Server appliance displays the detailed statistics for email attachments for the last 24 hours.
Syntax
show email-analysis attachment
Parameters
None
Output fields
The following table describes the output fields for the show email-analysis attachment command. Fields are listed in the approximate order in which they appear in the output.
Field | Description |
|---|---|
Total Attachments Submitted | Total number of attachments submitted for analysis. |
Objects Analyzed | Total number of attachments that have been analyzed. This number can be greater than the total number of attachments submitted if some of the objects are extracted from a ZIP file type or if attachments contain embedded objects. |
Objects identified as Malicious | Total number of attachments that were detected as malicious. |
Total events | Total number of events that were detected. |
Objects break down by system status | Total number of attachments with each system status type. |
Example
The following example shows summary information about email attachments.
hostname # show email-analysis attachment Attachments Statistics: Stats Time - Start Time: 2018/02/04 14:00:00 End Time: 2018/02/05 14:23:59 Total Attachments Submitted : 10102 Objects Analyzed : 10102 Objects identified as Malicious : 6 - VM verified : 6 - Duplicate to VM verified : 0 - Known checksum match : 0 Total events : 340 vm-signature-match events : 6 os-change-anomaly events : 216 checksum-match events : 113 vm-outbound-comm events : 5 Objects break down by system status, Total : 10102 Submitted for VM analysis : 5204 AE Submit Error : 1 Submit Disabled : 4896 Static Analysis Only : 1
User role
Admin, Operator, Monitor, or Analyst
Command mode
Enable
Supported appliances
This command was released as follows:
Email Security — Server: Before Release 6.4. The command output was enhanced to display the time period in Release 8.1.