show submission src <IP_address>

Prev Next

Displays the malware submission jobs based on a source IP address. You can display up to 100 jobs by default.

Syntax

show submission src <IP_address> [limit <number>]

Parameters

limit <number>

(Optional) Displays the specified number of entries that are based on a source IP address. A higher number might increase command response time.

Output fields

The following table describes the output fields for the show submission src command. Fields are listed in the approximate order in which they appear in the output.

Field

Description

Submission ID

Specific malware submission job number.

UUID

Specific universally unique identifier that is associated with the malware submission on an integrated Network Security appliance or an Network Security sensor.

Malware ID

Specific malware analysis job number.

Source IpAddress

IP address of the source.

Destination IpAddress

IP address of the destination.

File type

File type that is associated with the malware submission job.

Status

Whether the analysis succeeded or failed.

Malicious

Whether the malware submission job was detected as malicious.

Examples

The following example displays the malware submission job based on a particular source IP address:

hostname # show submission src 108.157.161.251
Submission ID: 9
   UUID                  : 750a471f-a60c-44f8-be91-a1030ce05c3b
   Malware ID            : 9
   Source IpAddress      : 108.157.161.251
   Destination IpAddress : 111.141.187.149
   md5sum                : 38323e5d6d131656d2ea0206b6f9bbdb
   File type             : exe
   Status                : timeout
   Malicious             : NO

User role

Administrator, Monitor, or Analyst.

Command mode

Enable

Supported appliances

This command is supported on the following appliances running the specified releases or later:

  • Malware Analysis: Release 7.7

  • File Protect: Release 7.7

  • Network Security: Release 7.7. The command output was enhanced to include total number of remote submissions on an Network Security sensor or sensor-enabled integrated appliance in Release 7.9.

  • Email Security — Server: Release 7.8