show web-analysis stats

Prev Next

Displays the statistics based on the Web traffic that the Network Security appliance monitors in your network.

Trellix Network Security, SmartVision Edition.This command is not supported on SmartVision Edition appliances, which are Network Security appliances with SmartVision Edition appliance licenses. The SmartVision sensor is also called show web-analysis greylists

Syntax

show web-analysis stats

Parameters

None

Output Fields

The following table describes the output fields for the show web-analysis stats command. Fields are listed in the approximate order in which they appear in the output.

Field

Description

Confirmed Incidents

Total number of incidents confirmed per minute for URLs.

Incidents

Total number of incidents generated per minute for URLs.

Workorders

Total number of work orders generated per minute for URLs

Sources

Total number of incoming source IP addresses seen per minute.

Flows

Total number of flows detected per minute.

PDFs

Total number of incoming PDFs detected per minute.

URLs

Total number of incoming URLs detected per minute.

Packets

Total number of incoming packets detected per second.

Gigabytes

Total number of gigabytes tracked per minute and per second.

Webpcaf Packet Loss

Percentage of packets in the queue or submitted to FireEye Unified Multiflow Engine (FUME) that were lost.

Internal Packet Loss

Percentage of packets that were dropped through Web traffic.

Total Packet Loss

Total percentage of packet loss.

Asymmetric Flows

Percentage of asymmetric flows that is monitored in Web traffic.

Missing Packet Flows

Percentage of packet flows that is monitored in Web traffic.

Data Loss

Percentage of data loss that is monitored in Web traffic.

Example

The following example displays the statistics based on the Web traffic that the Network Security appliance monitors in your network:

hostname # show web-analysis stats
Start: 9/11/15 23:39:32
Elapsed: 5002m 17.909s
Duration: 5002m 18.000s
Browsing Hours: 0.2hrs
Run Mode: normal
Average Greylist Priority Boost: 0.000
Priority File Version: 387
Correlation File Version: 339
Summary Statistics
Statistic                       Total           Rate/minute
Confirmed Incidents:             0                   0.000
Incidents:                       0                   0.000
Workorders:                      0                   0.000
Sources:                      1860                   0.372
Flows:                        1860                   0.372
PDFs:                            0                   0.000
URLs:                         1860                   0.372
Statistic                       Total           Rate/second
Packets:                    847420                    2.82 (all pkts)
Gigabytes:                    0.51                    0.00 (ether layer)
Gigabits:                     4.10                    0.00 (ether layer)
Webpcaf Packet Loss:    0.0
Internal Packet Loss:   0.0
Total Packet Loss:      0.0
Asymmetric Flows:       0.0
Missing Packet Flows:   0.0
Data Loss:              0.0

User role

Administrator, Operator, Monitor, or Analyst

Command mode

Enable

Supported appliances

This command is supported on the following appliances running the specified releases or later:

  • Network Security: Before Release 7.5. The command output was enhanced to display the additional statistics from FUME in Release 7.7.