show web-incident dst <IP_address>

Prev Next

Displays the Web incident jobs based on a destination IP address. You can display up to 100 jobs by default.

Syntax

show web-incident dst <IP_address> [limit <number>]

Parameters

limit <number>

(Optional) Displays the specified number of Web incident entries that are based on a destination IP address. A higher number might increase command response time.

Output fields

The following table describes the output fields for the show web-incident dst command. Fields are listed in the approximate order in which they appear in the output.

Field

Description

Web Incident ID

Specific Web incident job number.

Submission ID

Specific malware submission job number.

Submission name

Name of malware submission.

Source IpAddress

IP address of the source.

Destination IpAddress

IP address of the destination.

File type

File type that is associated with the malware submission job.

Status

Whether the analysis succeeded or failed.

Malicious

Whether the malware submission was detected as malicious.

Examples

The following example displays the Web incident job that is associated with the malware submission based on a particular destination IP address:

hostname # show web-incident dst 49.76.73.107
Web Incident ID: 5757
    Submission ID: 496
       Submission name       : http://utrust.in.ua/isj60tz/?3
       Source IpAddress      : 78.37.42.174
       Destination IpAddress : 49.76.73.107
       File type             : url
       Status                : success
       Malicious             : YES

User role

Admin, Monitor, or Analyst.

Command mode

Enable

Supported appliances

This command is supported on the following appliances running the specified releases or later:

  • Network Security: Release 7.7

  • Email Security — Server: Release 7.8