Displays the Web incident jobs based on a source IP address. You can display up to 100 jobs by default.
Syntax
show web-incident src <IP_address> [limit <number>]Parameters
limit <number>(Optional) Displays the specified number of Web incident entries that are based on a source IP address. A higher number might increase command response time.
Output fields
The following table describes the output fields for the show web-incident src command. Fields are listed in the approximate order in which they appear in the output.
Field | Description |
|---|---|
Web Incident ID | Specific Web incident job number. |
Submission ID | Specific malware submission job number. |
Submission name | Name of malware submission. |
Source IpAddress | IP address of the source. |
Destination IpAddress | IP address of the destination. |
File type | File type that is associated with the malware submission job. |
Status | Whether the analysis succeeded or failed. |
Malicious | Whether the malware submission job was detected as malicious. |
Examples
The following example displays the Web incident jobs based on a particular source IP address:
hostname # show web-incident src 75.82.32.248
Web Incident ID: 6201
Submission ID: 492
Submission name : http://aevego.com/R.html
Source IpAddress : 75.82.32.248
Destination IpAddress : 124.41.203.248
File type : url
Status : success
Malicious : YES
User role
Admin, Monitor, or Analyst.
Command mode
Enable
Supported appliances
This command is supported on the following appliances running the specified releases or later:
Network Security: Release 7.7
Email Security — Server: Release 7.8