Displays detailed information about a particular type of event. This command returns the event information such as the event's type, occurrence time, interface, action, analysis type, and so on. The event records are listed in descending order by event ID.
Syntax
show events type <event>
Parameters
<event>
vm-mw-execution—Displays information of the VM-verified malware execution.vm-outbound-comm—Displays information of the VM-verified outbound communication.exploit—Displays information of the signature match.vm-signature-match—Displays information of the VM Command and Control (CnC) signature match.checksum-match—Displays information of the binary checksum match.malware-callback—Displays information of the CnC signature match.os-change-anomaly—Displays information of the operating system change or anomaly.
Output fields
The following table describes the output fields for the show events type command. Fields are listed in the approximate order in which they appear in the output.
Field | Description |
|---|---|
Occurrence Time | Time that the event occurred. |
Interface | Type of interface that was active. |
Action | Type of action that was taken. The policy is specified in parentheses. |
Event Type | Type of event that was identified. |
Analysis Type | Type of analysis that is associated with an event. |
Trace ID | Specific trace job number that is associated with an event. |
Malware ID | Specific malware analysis job number. |
Source IP | IP address of the source. |
Destination IP | IP address of the destination. |
Source MAC | MAC address of the source. |
Destination MAC | MAC address of the destination. |
VLAN ID | Network VLAN job number that is associated with an event. |
Attacked Port | Port number that is associated with an attack. |
IP Protocol | Type of IP protocol that is used to transport the threat. |
Original Malware ID | If a malware sample is a duplicate of an original sample, the duplicate displays the information from the original malware analysis job number. |
PCAP URL | Packet capture (PCAP) link that is associated with an event. |
Event Page URL | Specific link that is associated with an event. |
Example
The following example displays partial output about the binary checksum match.
hostname # show events type checksum-match Event 15: Occurrence Time : 2015-09-30 23:49:35 PDT Interface : any Action : notified (default policy): 0 Event Type : checksum-match Analysis Type : Binary Analysis Trace ID : 2 Malware ID : 2 Source IP : 34.232.235.10 Destination IP : 44.142.250.4 Source MAC : 8A:2B:65:33:BD:E9 Destination MAC : 00:50:56:F0:7E:18 VLAN ID : 0 Attacked Port : 80 IP Protocol : tcp Original Malware ID : 0 Match Type : av-match Name : Mal/Generic-L EDP Page URL : https://mil.fireeye.com/edp.php?sname=Mal/Generic-L PCAP URL : https://172.16.146.84/event_stream/send_pcap_file?ev_id=15 PCAP URL (TEXT) : https://172.16.146.84/event_stream/send_pcap_ascii?ev_id=15 Event Page URL : https://172.16.146.84/event_stream/events?event_id=15 Event 3: Occurrence Time : 2015-09-30 23:45:15 PDT Interface : any Action : notified (default policy): 0 Event Type : checksum-match Analysis Type : Binary Analysis Trace ID : 1 Malware ID : 1 Source IP : 115.52.174.36 Destination IP : 124.151.168.211 Source MAC : 00:0C:29:28:84:3F Destination MAC : 00:03:47:4E:69:AA VLAN ID : 0 Attacked Port : 80 IP Protocol : tcp Original Malware ID : 0 Match Type : av-match Name : Mal/Whybo-A EDP Page URL : https://mil.fireeye.com/edp.php?sname=Mal/Whybo-A PCAP URL : https://172.16.146.84/event_stream/send_pcap_file?ev_id=3 PCAP URL (TEXT) : https://172.16.146.84/event_stream/send_pcap_ascii?ev_id=3 Event Page URL : https://172.16.146.84/event_stream/events?event_id=3
User role
Admin, Operator, Monitor, or Analyst
Command mode
Enable
Supported appliances
This command is supported on the following appliances running the specified releases or later:
Network Security: Before Release 7.5