Displays the Web incident jobs based on a destination IP address. You can display up to 100 jobs by default.
Syntax
show web-incident dst <IP_address> [limit <number>]Parameters
limit <number>(Optional) Displays the specified number of Web incident entries that are based on a destination IP address. A higher number might increase command response time.
Output fields
The following table describes the output fields for the show web-incident dst command. Fields are listed in the approximate order in which they appear in the output.
Field | Description |
|---|---|
Web Incident ID | Specific Web incident job number. |
Submission ID | Specific malware submission job number. |
Submission name | Name of malware submission. |
Source IpAddress | IP address of the source. |
Destination IpAddress | IP address of the destination. |
File type | File type that is associated with the malware submission job. |
Status | Whether the analysis succeeded or failed. |
Malicious | Whether the malware submission was detected as malicious. |
Examples
The following example displays the Web incident job that is associated with the malware submission based on a particular destination IP address:
hostname # show web-incident dst 49.76.73.107
Web Incident ID: 5757
Submission ID: 496
Submission name : http://utrust.in.ua/isj60tz/?3
Source IpAddress : 78.37.42.174
Destination IpAddress : 49.76.73.107
File type : url
Status : success
Malicious : YES
User role
Admin, Monitor, or Analyst.
Command mode
Enable
Supported appliances
This command is supported on the following appliances running the specified releases or later:
Network Security: Release 7.7
Email Security — Server: Release 7.8