Follow these steps to filter and sort the ICAP alerts grouped by infected host on the Hosts tab.
On the Hosts tab of the Network Security appliance, use the Filters panel on the left edge of the page to filter and sort the malware alerts and associated callback activity on ICAP traffic that was received on the ether1 or ether2 management interface. If the appliance has identified an ICAP alert, an ICAP badge appears in the Badges column.
Note
You can filter and sort the ICAP alerts only using the Web UI.
IPS Policies can be applied to the management interface. This will enable ICAP to detect IPS signatures.
Prerequisites
Administrator, Monitor, or Analyst access to the Network Security appliance
Make sure that the third-party device settings are configured so that the device can act as an ICAP client. For details, see ICAP client configuration prerequisites.
You have enabled the ICAP service on the Network Security appliance. For details, see Enabling or disabling ICAP service using the Web UI or Enabling or disabling ICAP service using the CLI.
You have enabled the request modification mode or response modification mode. For details, see Enabling or disabling ICAP request and response modification modes using the Web UI or Enabling or disabling ICAP request and response modification modes using the CLI.
You have configured the ICAP service settings so that the Network Security appliance can run an ICAP server. For details, see Configuring the ICAP server port and SSL certificate using the Web UI or Configuring the ICAP server port and SSL certificate using the CLI.
To clear all the ICAP alert filter settings, click Clear.
Choose Alerts > Alerts > Hosts.
To show the Filters panel, click the blue filter icon (
) in the upper-left corner of the main window.To change the time period, click the time field and select a different range in the Date Range drop-down menu:
Past Hour—ICAP alerts detected during the past 1 hour.
Past 24 Hours—ICAP alerts detected during the past 24 hours.
Past 1 Week—ICAP alerts detected during the past 1 week.
Past 2 Weeks—ICAP alerts detected during the past 2 weeks.
Past 1 Month—ICAP alerts detected during the past 1 month.
Past 3 Months—ICAP alerts detected during the past 3 months.
Past 1 Year—ICAP alerts detected during the past 1 year.
Custom—ICAP alerts detected for a custom time period that ranges from the last hour to the past 1 year.
To filter the ICAP badges, click the blue "V" on the right edge of the Badges option. Select the ICAP checkbox.
Click Apply.