Displays the statistics of malware objects (such as PDFs, EXEs, DLLs, or Microsoft Office files) based on the incoming Web traffic that the Network Security appliance monitors in your network. The Trellix Unified Multiflow Engine (FUME) allows the Network Security appliance to send suspicious URLs or objects to the virtual machine (VM) for a complete analysis.
Note
On SmartVision Edition appliances, which are Network Security appliances with SmartVision Edition appliance licenses, FUME statistics are based on malware objects detected in Web traffic transferred over SMB protocols in the core of the network (workstation to workstation or workstation to data center).
Syntax
show fume object stats
Parameters
None
Output fields
The following table describes the output fields for the show fume object stats command. Fields are listed in the approximate order in which they appear in the output.
Field | Description |
|---|---|
Start | Date and time when the appliance starts to send suspicious URLs or objects to the VM for analysis. |
Capture | Date and time when the statistics for incoming Web traffic were captured. |
Elapsed | Time elapsed since the start of the analysis. |
Poll | Number of minutes that the appliance polls for the most suspicious URLs or objects. |
WEB | Total number of URLs submitted per minute based on incoming Web traffic. |
OBJECT | Total number of particular malware objects submitted per minute based on incoming Web traffic. |
Example
The following example displays a summary of malware objects based on the incoming Web traffic that the Network Security appliance monitors in your network:
hostname # show fume object stats
Time:
Start: Thu Sep 17 15:57:08 2015
Capture: Thu Sep 17 16:44:58 2015
Elapsed: 47m 50s
Poll: 60s
Incoming Traffic Stats:
WEB Total Rate/min(avg) Rate/min(curr)
url 56 1.171 0.000
OBJECT Total Rate/min(avg) Rate/min(curr)
pdf_file 0 0.000 0.000
swf_file 8 0.167 0.000
cab 0 0.000 0.000
xml_file 0 0.000 0.000
exe 6 0.125 0.000
jnlp_file 0 0.000 0.000
xdp_file 0 0.000 0.000
js_file 0 0.000 0.000
img 0 0.000 0.000
chm 0 0.000 0.000
macho 0 0.000 0.000
xap 0 0.000 0.000
html_file 19 0.397 0.000
jar 0 0.000 0.000
hwp 0 0.000 0.000
class 0 0.000 0.000
xar 0 0.000 0.000
dmg 0 0.000 0.000
dll 0 0.000 0.000
User role
Admin, Operator, Monitor, or Analyst
Command mode
Enable
Supported appliances
This command is supported on the following appliance running the specified release or later:
Network Security: Release 7.7