show web-incident done

Prev Next

Displays a list of all the Web incident jobs that have been completed. This command returns information such as the type of file and status of the malware submission. You can display up to 100 jobs by default.

Syntax

show web-incident done [limit <number>]

Parameters

limit <number>

(Optional) Displays the specified number of Web incident jobs that have been completed. A higher number might increase command response time.

Output fields

The following table describes the output fields for the show web-incident done command. Fields are listed in the approximate order in which they appear in the output.

Field

Description

Web Incident ID

Specific web incident job number.

Submission ID

Specific malware submission job number.

Submission name

Name of malware submission.

Source IpAddress

IP address of the source.

Destination IpAddress

IP address of the destination.

Status

Whether the analysis succeeded or failed.

Malicious

Whether the malware submission job was detected as malicious.

Examples

The following example displays up to three Web incident jobs:

hostname # show web-incident done limit 3
Web Incident ID: 5782
    Submission ID: 523
       Submission name       : http://www.rxktpnjr.cjb.net/63bhputj/?2
       Source IpAddress      : 6.169.35.252
       Destination IpAddress : 93.7.86.79
       File type             : url
       Status                : success
       Malicious             : YES
Web Incident ID: 5779
    Submission ID: 520
       Submission name       : http://www.megaupload.com/?c=account&n=1
       Source IpAddress      : 103.106.113.43
       Destination IpAddress : 96.224.94.22
       File type             : url
       Status                : success
       Malicious             : NO
    Submission ID: 522
       Submission name       : http://www.megaupload.com/?c=filemanager
       Source IpAddress      : 103.106.113.43
       Destination IpAddress : 96.224.94.22
       File type             : url
       Status                : success
       Malicious             : NO

User role

Admin, Monitor, or Analyst.

Command mode

Enable

Supported appliances

This command is supported on the following appliances running the specified releases or later:

  • Network Security: Release 7.7

  • Email Security — Server: Release 7.8