Displays detailed information about events during a specified time period. This command returns the event information such as the event's type, occurrence time, interface, action, analysis type, and so on. The event records are listed in descending order by event ID.
Syntax
show events between <start_date> and <end_date>
Parameters
start_date
The start date of the events in the format yyyy/mm/dd.
end_date
The end date of the events in the format yyyy/mm/dd.
Output fields
The following table describes the output fields for the show events between command. Fields are listed in the approximate order in which they appear in the output.
Field | Description |
|---|---|
Occurrence Time | Time that the event occurred. |
Interface | Type of interface that was active. |
Action | Type of action that was taken. The policy is specified in parentheses. |
Event Type | Type of event that was identified. |
Analysis Type | Type of analysis that is associated with an event. |
Infected IP | IP address that is infected. |
C&C IP | IP address of the command and control (CnC) server. |
C&C Port | Port number of the CnC server. |
VLAN ID | Network VLAN job number that is associated with an event. |
Source MAC | MAC address of the source. |
Destination MAC | MAC address of the destination. |
IP Protocol | Type of IP protocol used to transport the threat. |
Original Malware ID | If a malware sample is a duplicate of an original sample, the duplicate displays the information from the original malware analysis job number. |
PCAP URL | Packet capture (PCAP) link that is associated with an event. |
Event Page URL | Specific link that is associated with an event. |
Example
The following example displays detailed information about events between a specified date.
hostname # show events between 2015/09/30 and 2015/10/01 Event 717: Occurrence Time : 2015-09-30 05:01:57 UTC Interface : A1 Action : flow permitted (default policy) Event Type : malware-callback Analysis Type : Content-Analysis Infected IP : 205.174.239.214 C&C IP : 63.35.171.59 C&C Port : 80 VLAN ID : 0 Source MAC : 00:1A:A0:70:2D:B0 Destination MAC : 00:17:DF:86:64:00 IP Protocol : tcp C&C Services : 1 63.35.171.59:6:80 [0] [fqc] GET /tred.html?sid=RB2tQ3wIqUgkW64YJwWuS3ENp0N2DqYccwSvTHFcr0l8CJ1adVmsHnYL-U50Wa8cdAz7H3xb-Uh0C6ZIdQX5S3Jb_RxGO61KdQ2uSkE3rkhxBK5McQ_uSUA-q05DP65PQjnzHXcNl390D6hLcTSWFC5crkp1Da9D HTTP/1.1 User-Agent: Mozilla/4.0 (compatible; MSIE 6.0) WinNT 5.1 Host: 82.98.235.209 Cache-Control: no-cache Malware-C&C Communication Profile ID : 33331100 Name : Trojan.Vundo EDP Page URL : https://mil.fireeye.com/edp.php?sname=Trojan.Vundo PCAP URL : https://172.17.74.50/event_stream/send_pcap_file?ev_id=717 PCAP URL (TEXT) : https://172.17.74.50/event_stream/send_pcap_ascii?ev_id=717 Event Page URL : https://172.17.74.50/event_stream/events?event_id=717 Event 716: Occurrence Time : 2015-09-30 05:01:57 UTC Interface : A1 Action : flow permitted (default policy) Event Type : malware-callback Analysis Type : Content-Analysis Infected IP : 205.174.239.214 C&C IP : 51.39.235.249 C&C Port : 80 VLAN ID : 0 Source MAC : 00:1A:A0:70:2D:B0 Destination MAC : 00:17:DF:86:64:00 IP Protocol : tcp C&C Services : 1 51.39.235.249:6:80 [0] [fqc] POST /frame.html?NyRPPgKAXwwl6t2xIqZK8kvLQBMdoSCsL4xTQ70H3WoyfkGWMD0saFUFcjMEBHsKMFglMQQxRgw0NEIJMDFDAzQ1Rkk5N0ITMJ5zAzQ HTTP/1.1 User-Agent: Mozilla/4.0 (compatible; MSIE 6.0) WinNT 5.1 Host: pancolp.com Content-Length: 164 Cache-Control: no-cache Malware-C&C Communication Profile ID : 33331100 Name : Trojan.Vundo EDP Page URL : https://mil.fireeye.com/edp.php?sname=Trojan.Vundo PCAP URL : https://172.17.74.50/event_stream/send_pcap_file?ev_id=716 PCAP URL (TEXT) : https://172.17.74.50/event_stream/send_pcap_ascii?ev_id=716 Event Page URL : https://172.17.74.50/event_stream/events?event_id=716 Event 620: Occurrence Time : 2015-10-01 00:00:07 UTC Interface : A1 Action : flow permitted (default policy) Event Type : malware-callback Analysis Type : Content-Analysis Infected IP : 21.95.174.173 C&C IP : 85.95.150.170 C&C Port : 80 VLAN ID : 0 Source MAC : 00:50:56:3C:50:49 Destination MAC : 00:09:0F:E2:A6:31 IP Protocol : tcp C&C Services : 1 85.95.150.170:6:80 [0] [fqc] POST /wp-content/languages/gate.php HTTP/1.0 Host: ebecbaltic.org Accept: */* Accept-Encoding: identity, *;q=0 Content-Length: 529 Connection: close Content-Type: application/octet-stream Content-Encoding: binary User-Agent: Mozilla/4.0 (compatible; MSIE 5.0; Windows 98) Malware-C&C Communication Profile ID : 67902082 Name : Trojan.Zbot EDP Page URL : https://mil.fireeye.com/edp.php?sname=Trojan.Zbot PCAP URL : https://172.17.74.50/event_stream/send_pcap_file?ev_id=620 PCAP URL (TEXT) : https://172.17.74.50/event_stream/send_pcap_ascii?ev_id=620 Event Page URL : https://172.17.74.50/event_stream/events?event_id=620
User role
Admin, Operator, Monitor, or Analyst
Command mode
Enable
Supported appliances
This command is supported on the following appliances running the specified releases or later:
Network Security: Before Release 7.5