Displays a full list of all incident jobs, in descending order by incident number. This command does not show incidents that were not confirmed to be malicious. For details about displaying a list of all malicious and nonmalicious events, see .
Syntax
show incident list
Parameters
None
Output fields
The following table describes the output fields for the show incident list command. Fields are listed in the approximate order in which they appear in the output.
Field | Description |
|---|---|
Incident | Specific confirmed incident job number. |
URLs | Number of URLs involved in the confirmed incident. |
Target OS | Guest image profile that was the target of the malware. |
App | Application that was the target of the malware. |
Page URL | Page URL submitted to the virtual machine (VM) as a confirmed incident. |
Source IP | IP address of the source. |
Noticed At | Date and time that the confirmed incident was seen. |
Example
The following example displays partial output of all Web incident jobs that are confirmed malicious:
hostname # show incident list
Incident E URL TargetOS App PageURL SrcIP Noti cedAt
-------------------------------------------------------------------------------- -----
6680 2 4 MWXP32-5 IE8.0 www.rxktpnjr.cjb.net/63bh 6.169.35.252 2015 -09-25 06:19:41 PDT
6673 5 3 MWXP32-5 IE6.0 de-my-page.info/forum/ind 103.169.252.110 2015 -09-25 06:13:02 PDT
6668 4 4 MWXP32-5 IE8.0 www.rxktpnjr.cjb.net/63bh 6.118.103.60 2015 -09-25 06:09:53 PDT
6667 1 1 MWXP32-5 IE6.0 de-my-page.info/forum/ccr 57.88.45.101 2015 -09-25 06:06:45 PDT
6663 1 7 MWXP32-5 IE8.0 kbl-ludwigsfelde.de/2014- 87.180.89.178 2015 -09-25 06:03:36 PDT
User role
Admin, Operator, Monitor, or Analyst
Command mode
Enable
Supported appliances
This command is supported on the following appliance running the specified release or later:
Network Security: Before Release 7.5