show events between

Prev Next

Displays detailed information about events during a specified time period. This command returns the event information such as the event's type, occurrence time, interface, action, analysis type, and so on. The event records are listed in descending order by event ID.

Syntax

show events between <start_date> and <end_date>

Parameters

start_date

The start date of the events in the format yyyy/mm/dd.

end_date

The end date of the events in the format yyyy/mm/dd.

Output fields

The following table describes the output fields for the show events between command. Fields are listed in the approximate order in which they appear in the output.

Field

Description

Occurrence Time

Time that the event occurred.

Interface

Type of interface that was active.

Action

Type of action that was taken. The policy is specified in parentheses.

Event Type

Type of event that was identified.

Analysis Type

Type of analysis that is associated with an event.

Infected IP

IP address that is infected.

C&C IP

IP address of the command and control (CnC) server.

C&C Port

Port number of the CnC server.

VLAN ID

Network VLAN job number that is associated with an event.

Source MAC

MAC address of the source.

Destination MAC

MAC address of the destination.

IP Protocol

Type of IP protocol used to transport the threat.

Original Malware ID

If a malware sample is a duplicate of an original sample, the duplicate displays the information from the original malware analysis job number.

PCAP URL

Packet capture (PCAP) link that is associated with an event.

Event Page URL

Specific link that is associated with an event.

Example

The following example displays detailed information about events between a specified date.

hostname # show events between 2015/09/30 and 2015/10/01
Event 717:
   Occurrence Time        : 2015-09-30 05:01:57 UTC
   Interface              : A1
   Action                 : flow permitted (default policy)
   Event Type             : malware-callback
   Analysis Type          : Content-Analysis
      Infected IP         : 205.174.239.214
      C&C IP              : 63.35.171.59
      C&C Port            : 80
      VLAN ID             : 0
      Source MAC          : 00:1A:A0:70:2D:B0
      Destination MAC     : 00:17:DF:86:64:00
      IP Protocol         : tcp
   C&C Services           : 1
      63.35.171.59:6:80 [0] [fqc]
         GET /tred.html?sid=RB2tQ3wIqUgkW64YJwWuS3ENp0N2DqYccwSvTHFcr0l8CJ1adVmsHnYL-U50Wa8cdAz7H3xb-Uh0C6ZIdQX5S3Jb_RxGO61KdQ2uSkE3rkhxBK5McQ_uSUA-q05DP65PQjnzHXcNl390D6hLcTSWFC5crkp1Da9D HTTP/1.1
         User-Agent: Mozilla/4.0 (compatible; MSIE 6.0) WinNT 5.1
         Host: 82.98.235.209
         Cache-Control: no-cache
   Malware-C&C Communication Profile
      ID                  : 33331100
      Name                : Trojan.Vundo
      EDP Page URL        : https://mil.fireeye.com/edp.php?sname=Trojan.Vundo
      PCAP URL            : https://172.17.74.50/event_stream/send_pcap_file?ev_id=717
      PCAP URL (TEXT)     : https://172.17.74.50/event_stream/send_pcap_ascii?ev_id=717
      Event Page URL      : https://172.17.74.50/event_stream/events?event_id=717
Event 716:
   Occurrence Time        : 2015-09-30 05:01:57 UTC
   Interface              : A1
   Action                 : flow permitted (default policy)
   Event Type             : malware-callback
   Analysis Type          : Content-Analysis
      Infected IP         : 205.174.239.214
      C&C IP              : 51.39.235.249
      C&C Port            : 80
      VLAN ID             : 0
      Source MAC          : 00:1A:A0:70:2D:B0
      Destination MAC     : 00:17:DF:86:64:00
      IP Protocol         : tcp
   C&C Services           : 1
      51.39.235.249:6:80 [0] [fqc]
         POST /frame.html?NyRPPgKAXwwl6t2xIqZK8kvLQBMdoSCsL4xTQ70H3WoyfkGWMD0saFUFcjMEBHsKMFglMQQxRgw0NEIJMDFDAzQ1Rkk5N0ITMJ5zAzQ HTTP/1.1
         User-Agent: Mozilla/4.0 (compatible; MSIE 6.0) WinNT 5.1
         Host: pancolp.com
         Content-Length: 164
         Cache-Control: no-cache
   Malware-C&C Communication Profile
      ID                  : 33331100
      Name                : Trojan.Vundo
      EDP Page URL        : https://mil.fireeye.com/edp.php?sname=Trojan.Vundo
      PCAP URL            : https://172.17.74.50/event_stream/send_pcap_file?ev_id=716
      PCAP URL (TEXT)     : https://172.17.74.50/event_stream/send_pcap_ascii?ev_id=716
      Event Page URL      : https://172.17.74.50/event_stream/events?event_id=716
Event 620:
   Occurrence Time        : 2015-10-01 00:00:07 UTC
   Interface              : A1
   Action                 : flow permitted (default policy)
   Event Type             : malware-callback
   Analysis Type          : Content-Analysis
      Infected IP         : 21.95.174.173
      C&C IP              : 85.95.150.170
      C&C Port            : 80
      VLAN ID             : 0
      Source MAC          : 00:50:56:3C:50:49
      Destination MAC     : 00:09:0F:E2:A6:31
      IP Protocol         : tcp
   C&C Services           : 1
      85.95.150.170:6:80 [0] [fqc]
         POST /wp-content/languages/gate.php HTTP/1.0
         Host: ebecbaltic.org
         Accept: */*
         Accept-Encoding: identity, *;q=0
         Content-Length: 529
         Connection: close
         Content-Type: application/octet-stream
         Content-Encoding: binary
         User-Agent: Mozilla/4.0 (compatible; MSIE 5.0; Windows 98)
   Malware-C&C Communication Profile
      ID                  : 67902082
      Name                : Trojan.Zbot
      EDP Page URL        : https://mil.fireeye.com/edp.php?sname=Trojan.Zbot
      PCAP URL            : https://172.17.74.50/event_stream/send_pcap_file?ev_id=620
      PCAP URL (TEXT)     : https://172.17.74.50/event_stream/send_pcap_ascii?ev_id=620
      Event Page URL      : https://172.17.74.50/event_stream/events?event_id=620

User role

Admin, Operator, Monitor, or Analyst

Command mode

Enable

Supported appliances

This command is supported on the following appliances running the specified releases or later:

  • Network Security: Before Release 7.5