show email-analysis attachment from

Prev Next

Displays the cumulative statistics such as the total number of suspicious attachments that were submitted to the virtual machine for analysis, the total number of attachments that were detected as malicious, the total number of events that were detected, and the total number of attachments with each system status type during a specified time period.

By default, the Email Security — Server appliance displays the detailed statistics for email attachments for the last 24 hours.

Note

The output of the show email-analysis attachment from command and show email-analysis attachment since command may show a different time period from the time period that you specified. This discrepancy could be due to when data is available.

Syntax

show email-analysis attachment from <start_date> <start_time> to <end_date> <end_time>

Parameters

start_date

Displays the statistics for email attachments starting from this date. Start date is specified in the format of yyyy/mm/dd.

start_time

Displays the statistics for email attachments starting from this time. Start time is specified in the format of hh:mm:ss.

end_date

Displays the statistics for email attachments ending on this date. End date is specified in the format of yyyy/mm/dd.

end_time

Displays the statistics for email attachments ending at this time. End time is specified in the format of hh:mm:ss.

Output fields

The following table describes the output fields for the show email-analysis attachment from command. Fields are listed in the approximate order in which they appear in the output.

Field

Description

Total Attachments Submitted

Total number of attachments submitted for analysis.

Objects analyzed

Total number of attachments that have been analyzed. This number can be greater than the total number of attachments submitted if some of the objects are extracted from a ZIP file type or if attachments contain embedded objects.

Objects identified as Malicious

Total number of attachments that were detected as malicious.

Total events

Total number of events that were detected.

Objects break down by system status

Total number of attachments with each system status type.

Example

The following example displays the statistics for email attachments that have been submitted starting on 2017/11/24 and ending on 2017/12/29.

hostname # show email-analysis attachment from 2017/11/27 00:00:00 to 2017/12/29 00:00:00
Attachments Statistics:
Stats Time - Start Time: 2017/12/12 16:00:00   End Time: 2017/12/29 00:00:00

Total Attachments Submitted :       4
   Objects Analyzed                         :       5
   Objects identified as Malicious          :       1
      - VM verified                         :       1
      - Duplicate to VM verified            :       0
      - Known checksum match                :       0

Total events                                :      11
   os-change-anomaly  events                :       8
   vm-outbound-comm   events                :       2
   checksum-match     events                :       1 

Objects break down by system status, Total  :       5
   Submitted for VM analysis                :       5

User role

Admin, Analyst, Operator, or Monitor

Command mode

Enable

Supported appliances

This command is supported on the following appliances running the specified releases or later:

  • Email Security — Server: Release 8.1