show web-incident src <IP_address>

Prev Next

Displays the Web incident jobs based on a source IP address. You can display up to 100 jobs by default.

Syntax

show web-incident src <IP_address> [limit <number>]

Parameters

limit <number>

(Optional) Displays the specified number of Web incident entries that are based on a source IP address. A higher number might increase command response time.

Output fields

The following table describes the output fields for the show web-incident src command. Fields are listed in the approximate order in which they appear in the output.

Field

Description

Web Incident ID

Specific Web incident job number.

Submission ID

Specific malware submission job number.

Submission name

Name of malware submission.

Source IpAddress

IP address of the source.

Destination IpAddress

IP address of the destination.

File type

File type that is associated with the malware submission job.

Status

Whether the analysis succeeded or failed.

Malicious

Whether the malware submission job was detected as malicious.

Examples

The following example displays the Web incident jobs based on a particular source IP address:

hostname # show web-incident src 75.82.32.248
Web Incident ID: 6201
    Submission ID: 492
       Submission name       : http://aevego.com/R.html
       Source IpAddress      : 75.82.32.248
       Destination IpAddress : 124.41.203.248
       File type             : url
       Status                : success
       Malicious             : YES

User role

Admin, Monitor, or Analyst.

Command mode

Enable

Supported appliances

This command is supported on the following appliances running the specified releases or later:

  • Network Security: Release 7.7

  • Email Security — Server: Release 7.8