Viewing custom feed details grouped by alert using the Web UI

Prev Next

The Alerts > Alerts > Alerts page lists the details of the event results table, grouped by alert, of the malware events that matched the name of the custom blacklist feed that you imported on a managed Network Security appliance from the Central Management System appliance. You can drill down to identify matched traffic that was either blocked or not blocked for the following types of malware:

  • Domain Match—Domain that matches the name of the feed that contains the entries of known suspicious or malicious domains that you imported.

  • Infection Match—Pattern that matches the name of the feed that contains entries of known suspicious or malicious URLs or IP addresses that you imported.

  • Malware Object—Hash that matches the name of the feed that contains entries of MD5 or SHA-256 file types that you imported.

To view the custom feed details grouped by alert on a managed Network Security appliance:
  1. Log in to the managed Network Security Web UI.

  2. Choose Alerts > Alerts > Alerts.

  3. To expand an entry, click the alert type in the Alert Type column.

    Note

    Local feed data is automatically removed when the corresponding locally generated rules (localsig rules) expire. You cannot delete local feed data.