View the file analysis results on the Analysis Reports page. In dynamic analysis if you have selected multiple VM profiles, the file has one Job ID and separate Task IDs for each VM profile. In Static Analysis, when a sample is detected then only one entry with one Job ID and one Task ID is created.
Note
Older reports are deleted when the data disk of Intelligent Sandbox is 75% full. You can view the current data disk space available in the System Health monitor of the Dashboard. If you configure the options under FTP Result Output in the User Management page and use the
set resultbackup enablecommand, then Intelligent Sandbox saves the results locally and sends them to the configured FTP server for your long-term use.To save the FTP results for a longer time period, configure the FTP Result Output settings, then enable
set resultbackupfrom the Intelligent Sandbox CLI.To extract the results from a ATD generated backup:
Copy the backup to an external FTP.
Unzip the backup with the Support bundle password. You must contact Trellix Support for the password.
The results folder is found under vedata/amas/results. The following path is appended with the username of the sample submission and the submission date.
vedata/amas/results/admin/2024-03-19/FFCB5DE11310A8E7D2243F22873932BA-11208944-386/AnalysisLog
While you view the reports, the maximum number of reports you can navigate to are one million. If you want to view the reports beyond that, use the search filter to reduce the result of the number of reports.
Log on to the Intelligent Sandbox web interface.
Click → .
The Analysis Reports page lists the status for the completed files.
Note
If you do not have administrator permissions, only those files that you submitted are listed. A user with admin permissions can view the samples submitted by all users.
Click Export CSV to export locally the status of completed files in CSV format and then click Download CSV.
Note
You can export a maximum of 1 million records by using Export CSV operation.
The CSV report is downloaded and the CSV file is zipped in the
results.zipfile.Specify the criteria for viewing and refreshing the records in the Analysis Reports page.
Set the criteria to display records in the Analysis Reports page.
By default, the results for the files completed in the last 24 hours are shown.
You can specify this criteria based on time or number. For example, you can select to view the files for which the analysis was completed in the last 5 minutes or for the last 100 completed files.
Set the frequency at which the Analysis Reports page must refresh itself.
The default refresh interval is 1 minute.
To refresh the Analysis Reports page now, click
.
Choose to hide the columns that you do not require.
Move the mouse over the right corner of a column heading and click the drop-down arrow.
Select Columns.
Select only the needed column names from the list.
Note
You can click a column heading and drag it to the needed position.
To sort the records based on a particular column name, click the column heading.
You can sort the records in the ascending or descending order. Or, move the mouse over the right corner of a column heading and click the drop-down arrow. Then select Sort Ascending or Sort Descending.
By default, high severity files are shown at the top of the list.
To save the Analysis Reports page settings, click
