Displays information for a specific Web analysis incident job that is confirmed as malicious on the appliance. This command does not show incident information that was not deemed malicious. For details about displaying a list of all malicious and nonmalicious events, see .
Syntax
show incident <incident_ID>
Parameters
None
Output fields
The following table describes the output fields for the show incident command. Fields are listed in the approximate order in which they appear in the output.
Field | Description |
|---|---|
Web Analysis Incident | Specific Web analysis incident job number. |
Target OS | Guest image profile that was the target of the malware. |
Target Application | Application that was the target of the malware. |
Page URL | Page URL submitted to the virtual machine (VM) as a confirmed incident. |
Source IP | IP address of the source. |
Noticed At | Date and time that the confirmed incident was seen. |
Updated At | Date and time that the confirmed incident was updated. |
Events found | Number of events involved in the confirmed incident. |
URLs | Number of URLs involved in the confirmed incident. |
ContentType | Type of retrieved object, such as application or text. |
Example
The following example displays the information about job number 6680:
hostname # show incident 6680
Web Analysis Incident: 6680
Target OS : Microsoft WindowsXP 32-bit 5.1 sp3 15.0826
Target Application : InternetExplorer 8.0
Page URL : www.rxktpnjr.cjb.net/63bhputj/?2
Source IP : 6.169.35.252
Noticed At : 2015-09-25 06:19:41 PDT
Updated At : 2015-09-25 06:21:58 PDT
Events found : (2) 1581(NA) 1580(OS)
URLs : (4)
ContentType URL
--------------------------
appl/octet-stream www.rxktpnjr.cjb.net/63bhputj/?2dc6ba8fd447903e571c060d5
text/html www.rxktpnjr.cjb.net/63bhputj/?2dc6ba8fd447903e571c060d5
text/html www.rxktpnjr.cjb.net/63bhputj/?2
appl/octet-stream www.rxktpnjr.cjb.net/63bhputj/?362f56117ea4eb38415e5b5d0
User role
Admin, Operator, Monitor, or Analyst
Command mode
Enable
Supported appliances
This command is supported on the following appliance running the specified release or later:
Network Security: Before Release 7.5