show web-incident limit

Prev Next

Displays information for the specified number of Web incident jobs. You can display up to 100 jobs by default.

Syntax

show web-incident limit <number>

Parameters

<number>

Number of entries that are displayed. A higher number might increase command response time.

Output fields

The following table describes the output fields for the show web-incident limit command. Fields are listed in the approximate order in which they appear in the output.

Field

Description

Web Incident ID

Specific Web incident job number.

Submission ID

Specific malware submission job number.

Submission name

Name of malware submission.

Source IpAddress

IP address of the source.

Destination IpAddress

IP address of the destination.

File type

File type that is associated with the malware submission job.

Status

Whether the analysis succeeded or failed.

Malicious

Whether the malware submission was detected as malicious.

Examples

The following example displays the information for five Web incident jobs:

hostname # show web-incident limit 5
Web Incident ID: 2435446
    Submission ID: 139075
       Submission name       : http://www.popularmechanics.com/
       Source IpAddress      : 128.31.190.67
       Destination IpAddress : 128.118.22.183
       File type             : url
       Status                : running
Web Incident ID: 2435268
    Submission ID: 139069
       Submission name       : http://coolrom.com/roms/snes/
       Source IpAddress      : 128.95.251.173
       Destination IpAddress : 128.180.218.181
       File type             : url
       Status                : no_profile_match
       Malicious             : NO
Web Incident ID: 2435584
    Submission ID: 139070
       Submission name       : http://r13---sn-a5m7lner.c.youtube.com/videoplayback?id=a7d9a6861ff0be40&itag=134&source=youtube&cp=U0hVSFRTV19KUENONV9MTUFKOnBpYldtSVRRbnVT&ratebypass=yes&gir=yes&clen=5123910&lmt=1360904184336838&sver=3&fexp=932200,914051,916611,930501,920704,912806,902000,919512,929901,913605,906938,931202,931203,931401,908529,930803,920201,929602,930101,930603,900824&upn=w0qWqUxaQFg&cpn=7zmR0HJGIfvqGTdl&ip=137.151.175.186&ipbits=8&expire=1363489956&sparams=ip,ipbits,expire,id,itag,source,cp,ratebypass,gir,clen,lmt&signature=3AAA3D5EF852A0301B453DD6DB7A661614D89A4A.03D27
       Source IpAddress      : 128.53.30.85
       Destination IpAddress : 128.100.245.179
       File type             : url
       Status                : running
Web Incident ID: 2435578
    Submission ID: 139063
       Submission name       : http://crossdresserdate.xmatch.com/p/main.cgi?dcb=crossdresserdate.xmatch.com
       Source IpAddress      : 128.84.48.36
       Destination IpAddress : 128.191.12.159
       File type             : url
       Status                : running
Web Incident ID: 2435592
    Submission ID: 139079
       Submission name       : http://csearch.naver.com/twitter/search.naver?where=uio&is_utf8=1&display=1&q_me2User=tymee&q_twitUser=tymee_&uio_type=1&_callback=nhn.uio.snsgroup_ellipsis.callback
       Source IpAddress      : 128.144.66.141
       Destination IpAddress : 128.7.31.101
       File type             : url
       Status                : running

User role

Admin, Monitor, or Analyst.

Command mode

Enable

Supported appliances

This command is supported on the following appliances running the specified releases or later:

  • Network Security: Release 7.7

  • Email Security — Server: Release 7.8