The Alerts > Alerts > Alerts page lists the details of the event results table, grouped by alert type, of the malware events that matched the custom blacklist feed. Each feed name is listed as the malware name.
You can drill down to identify matched traffic that was either blocked or not blocked for the following types of malware:
Domain Match—Domain that matches the name of the feed that contains the entries of known suspicious or malicious domains that you imported.
Infection Match—Pattern that matches the name of the feed that contains entries of known suspicious or malicious URLs or IP addresses that you imported.
Malware Object—Hash that matches the name of the feed that contains entries of MD5 or SHA-256 file types that you imported.
A File Protect appliance deployed in TAP mode or inline mode.
Admin access to the File Protect appliance.
A connection from the appliance to the Dynamic Threat Intelligence (DTI) Cloud.
A flat file or an XML-based file in STIX 1.2 format that contains custom blacklist entries. The file must be accessible from the local desktop from which you access the appliance Web UI.
For details, see Creating a custom blacklist from third-party feeds.
One or more third-party feeds uploaded to the appliance from a flat file or an XML-based file in STIX 1.2 format.
For details, see Uploading a third-party feed using the Web UI.
Log in to the standalone appliance Web UI.
Choose Alerts > Alerts > Alerts.
To expand an entry, click the alert type in the Alert Type column.
Note
Local feed data is automatically removed when the corresponding locally generated rules (localsig rules) expire. You cannot delete local feed data.