Displays the cumulative statistics such as the total number of suspicious URLs that were submitted to the virtual machine for analysis, the total number of URLs that were detected as malicious, the total number of events that were detected, and the total number of URLs with each system status type during a specified time period.
By default, the Email Security — Server appliance displays the detailed statistics for email URLs for the last 24 hours.
Note
The output of the
show email-analysis url fromcommand andshow email-analysis url sincecommand may show a different time period from the time period that you specified. This discrepancy could be due to when data is available.
Syntax
show email-analysis url from <start_date> <start_time> to <end_date> <end_time>
Parameters
start_date
Displays the statistics for email URLs starting from this date. Start date is specified in the format of yyyy/mm/dd.
start_time
Displays the statistics for email URLs starting from this time. Start time is specified in the format of hh:mm:ss.
end_date
Displays the statistics for email URLs ending on this date. End date is specified in the format of yyyy/mm/dd.
end_time
Displays the statistics for email URLs ending at this time. End time is specified in the format of hh:mm:ss.
Output fields
The following table describes the output fields for the show email-analysis url from command. Fields are listed in the approximate order in which they appear in the output.
Field | Description |
|---|---|
Total URLs Submitted | Total number of URLs submitted for analysis. |
Objects Analyzed | Total number of URLs that have been analyzed. |
Objects identified as Malicious | Total number of URLs that were detected as malicious. |
Total events | Total number of events that were detected. |
Objects break down by system status | Total number of URLs with each system status type. This field also displays the number of URLs that were submitted to the virtual machine for dynamic analysis. |
Example
The following example displays the statistics for email URLs that have been submitted starting on 2017/11/24 and ending on 2017/12/29.
hostname # show email-analysis url from 2017/11/24 15:00:00 to 2017/12/29 15:00:00 URLs Statistics: Stats Time - Start Time: 2017/12/12 16:00:00 End Time: 2017/12/29 15:00:00 Total URLs Submitted : 28 Objects Analyzed : 7 Objects identified as Malicious : 6 - VM verified : 6 - Duplicate to VM verified : 0 - Known checksum match : 6 Total events : 13 os-change-anomaly events : 2 vm-outbound-comm events : 2 checksum-match events : 9 Objects break down by system status, Total : 7 Submitted for VM analysis : 7
User role
Admin, Analyst, Operator, or Monitor
Command mode
Enable
Supported appliances
This command is supported on the following appliances running the specified releases or later:
Email Security — Server: Release 8.1