show email-analysis attachment since

Prev Next

Displays the cumulative statistics such as the total number of suspicious attachments that were submitted to the virtual machine for analysis, the total number of attachments that were detected as malicious, the total number of events that were detected, and the total number of attachments with each system status type from a specified time up to the present.

By default, the Email Security — Server appliance displays the detailed statistics for email attachments for the last 24 hours.

Note

The output of the show email-analysis attachment from command and show email-analysis attachment since commands may show a different time period from the time period that you specified. This discrepancy could be due to when data is available.

Syntax

show email-analysis attachment since <number> {days | hours | minutes | seconds}

Parameters

<number {days | hours | minutes | since}

Shows statistics for email attachments during this number of days, hours, minutes, or seconds.

days

Displays statistics for email attachments during a specified number of days.

hours

Displays statistics for email attachments during a specified number of hours.

minutes

Displays statistics for email attachments during a specified number of minutes.

seconds

Displays statistics for email attachments during a specified number of seconds.

Output fields

The following table describes the output fields for the show email-analysis attachment since command. Fields are listed in the approximate order in which they appear in the output.

Field

Description

Total Attachments Submitted

Total number of attachments submitted for analysis.

Objects Analyzed

Total number of attachments that have been analyzed. This number can be greater than the total number of attachments submitted if some of the objects are extracted from a ZIP file type or if attachments contain embedded objects.

Objects identified as Malicious

Total number of attachments that were detected as malicious.

Total events

Total number of events that were detected.

Objects break down by system status

Total number of attachments with each system status type.

Example

The following example displays the statistics for email attachments that have been submitted in the past 20 days.

hostname # show email-analysis attachment since 20 days
Attachments Statistics:
Stats Time - Start Time: 2017/12/29 11:00:00   End Time: 2018/01/18 11:26:52

Total Attachments Submitted :      50
   Objects Analyzed                         :      58
   Objects identified as Malicious          :      28
      - VM verified                         :      28
      - Duplicate to VM verified            :       0
      - Known checksum match                :      19

Total events                                :     121
   vm-signature-match events                :      17
   os-change-anomaly  events                :      37
   checksum-match     events                :      41
   vm-outbound-comm   events                :      26

Objects break down by system status, Total  :      58
   Submitted for VM analysis                :      50
   Invalid                                  :       8

User role

Administrator, Analyst, Operator, or Monitor

Command mode

Enable

Supported appliances

This command is supported on the following appliances running the specified releases or later:

  • Email Security — Server: Release 8.1