show events on

Prev Next

Displays detailed information about events that occurred on a specified date. This command returns the event information such as the event's type, occurrence time, interface, action, analysis type, and so on. The event records are listed in descending order by event ID.

Syntax

show events on <date>

Parameters

<date>

Displays the events that occurred on this date. Date is specified in the format yyyy/mm/dd.

Output fields

The following table describes the output fields for the show events on command. Fields are listed in the approximate order in which they appear in the output.

Field

Description

Occurrence Time

Time that the event occurred.

Interface

Type of interface that was active.

Action

Type of action that was taken. The policy is specified in parentheses.

Event Type

Type of event that was identified.

Analysis Type

Type of analysis that is associated with an event.

Trace ID

Specific trace job number that is associated with an event.

Malware ID

Specific malware analysis job number.

Source IP

IP address of the source.

Destination IP

IP address of the destination.

Source MAC

MAC address of the source.

Destination MAC

MAC address of the destination.

VLAN ID

Network VLAN job number that is associated with an event.

Attacked Port

Port number that is associated with an attack.

IP Protocol

Type of IP protocol that is used to transport the threat.

Original Malware ID

If a malware sample is a duplicate of an original sample, the duplicate displays the information from the original malware analysis job number.

PCAP URL

Packet capture (PCAP) link that is associated with an event.

Event Page URL

Specific link that is associated with an event.

Example

The following example displays detailed information about events that occurred on the specified date.

hostname # show events on 2015/09/30
Event 3:
   Occurrence Time        : 2015-09-30 23:45:15 PDT
   Interface              : any
   Action                 : notified (default policy): 0
   Event Type             : checksum-match
   Analysis Type          : Binary Analysis
   Trace ID               : 1
   Malware ID             : 1
      Source IP           : 115.52.174.36
      Destination IP      : 124.151.168.211
      Source MAC          : 00:0C:29:28:84:3F
      Destination MAC     : 00:03:47:4E:69:AA
      VLAN ID             : 0
      Attacked Port       : 80
      IP Protocol         : tcp
      Original Malware ID : 0
      Match Type          : av-match
      Name                : Mal/Whybo-A
      EDP Page URL        : https://mil.fireeye.com/edp.php?sname=Mal/Whybo-A
      PCAP URL            : https://172.16.146.84/event_stream/send_pcap_file?ev_id=3
      PCAP URL (TEXT)     : https://172.16.146.84/event_stream/send_pcap_ascii?ev_id=3
      Event Page URL      : https://172.16.146.84/event_stream/events?event_id=3
Event 2:
   Occurrence Time        : 2015-09-30 23:44:33 PDT
   Interface              : A2
   Action                 : flow permitted (default policy)
   Event Type             : exploit
   Analysis Type          : Content-Analysis
   Trace ID               : 0
      Source IP           : 34.232.235.10
      Destination IP      : 44.142.250.4
      Source MAC          : 8A:2B:65:33:BD:E9
      Destination MAC     : 00:50:56:F0:7E:18
      VLAN ID             : 0
      Attacked Port       : 80
      IP Protocol         : tcp
   Infection Communication Profile
      ID                  : 84500406
      Name                : Exploit.Kit.Goon
      EDP Page URL        : https://mil.fireeye.com/edp.php?sname=Exploit.Kit.Goon
      PCAP URL            : https://172.16.146.84/event_stream/send_pcap_file?ev_id=2
      PCAP URL (TEXT)     : https://172.16.146.84/event_stream/send_pcap_ascii?ev_id=2
      Event Page URL      : https://172.16.146.84/event_stream/events?event_id=2
Event 1:
   Occurrence Time        : 2015-09-30 23:42:59 PDT
   Interface              : A2
   Action                 : notified (default policy): 0
   Event Type             : malware-callback
   Analysis Type          : Content-Analysis
      Infected IP         : 84.26.164.204
      C&C IP              : 0.0.0.0
      C&C Port            : 0
      VLAN ID             : 0
      Source MAC          : 00:E0:81:40:32:08
      Destination MAC     : 00:09:3D:13:AC:EE
      IP Protocol         : udp
   C&C Services           : 1
      img121.imagehacks.biz:17:53 [0]
   Malware-C&C Communication Profile
      ID                  : 80442782
      Name                : Bot.Mariposa.DNS
      EDP Page URL        : https://mil.fireeye.com/edp.php?sname=Bot.Mariposa.DNS
      PCAP URL            : https://172.16.146.84/event_stream/send_pcap_file?ev_id=1
      PCAP URL (TEXT)     : https://172.16.146.84/event_stream/send_pcap_ascii?ev_id=1
      Event Page URL      : https://172.16.146.84/event_stream/events?event_id=1

User role

Admin, Operator, Monitor, or Analyst

Command mode

Enable

Supported appliances

This command is supported on the following appliances running the specified releases or later:

  • Network Security: Before Release 7.5