This URL is used to retrieve the malware statistics grouped by engines for a Sensor.
Resource URL
GET /sensor/{sensorId}/trafficstats/malwarestatsgroupbyengine
Request Parameters
URL Parameters:
Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| Sensor id | Number | Yes |
Response Parameters
Following fields are returned if the request parameters are correct, otherwise error details are returned.
Field Name | Description | Data Type |
|---|---|---|
| Name of the engine for which the statistics(values) is given | String |
| Values of traffic statistics parameters for the given engine | Object |
Details of values:
Field Name | Description | Data Type |
|---|---|---|
| Number of files submitted | String |
| Number of files ignored | String |
| Number of files processed | String |
| Number of ATD files dropped | String |
| Number of ATD static analysis | String |
| Number of ATD dynamic analysis | String |
| Number of ATD cache references | String |
| Number of clean files out of all the files submitted | String |
| Number of files with very high malware confidence matches | String |
| Number of files with high malware confidence matches | String |
| Number of files with medium malware confidence matches | String |
| Number of files with low malware confidence matches | String |
| Number of files with very low malware confidence matches | String |
| Number of files with unknown malware confidence matches | String |
| Number of alerts generated | String |
| Number of files blocked | String |
| Number of connection resets | String |
Example
Request
GET https://<NSM_IP>/sdkapi/sensor/1009/trafficstats/malwarestatsgroupbyengine
Response
{
"mlawareEngineTrafficStats":[
{
"engine":"Blocklist",
"values":{
"filesSubmitted":0,
"filesIgnored":0,
"filesProcessed":0,
"atdFilesDroppedUnderLoad":0,
"atdStaticAnalysis":0,
"atdDynamicAnalysis":0,
"atdCacheReferences":0,
"cleanFiles":0,
"veryHighMalwareConfidenceMatches":0,
"highMalwareConfidenceMatches":0,
"mediumMalwareConfidenceMatches":0,
"lowMalwareConfidenceMatches":0,
"veryLowMalwareConfidenceMatches":0,
"unknownMalwareConfidenceMatches":0,
"alertsGenerated":0,
"filesBlocked":0,
"connectionsReset":0
}
},
{
"engine":"GTI File Reputation",
"values":{
"filesSubmitted":0,
"filesIgnored":0,
"filesProcessed":0,
"atdFilesDroppedUnderLoad":0,
"atdStaticAnalysis":0,
"atdDynamicAnalysis":0,
"atdCacheReferences":0,
"cleanFiles":0,
"veryHighMalwareConfidenceMatches":0,
"highMalwareConfidenceMatches":0,
"mediumMalwareConfidenceMatches":0,
"lowMalwareConfidenceMatches":0,
"veryLowMalwareConfidenceMatches":0,
"unknownMalwareConfidenceMatches":0,
"alertsGenerated":0,
"filesBlocked":0,
"connectionsReset":0
}
},
{
"engine":"PDFEmulation",
"values":{
"filesSubmitted":0,
"filesIgnored":0,
"filesProcessed":0,
"atdFilesDroppedUnderLoad":0,
"atdStaticAnalysis":0,
"atdDynamicAnalysis":0,
"atdCacheReferences":0,
"cleanFiles":0,
"veryHighMalwareConfidenceMatches":0,
"highMalwareConfidenceMatches":0,
"mediumMalwareConfidenceMatches":0,
"lowMalwareConfidenceMatches":0,
"veryLowMalwareConfidenceMatches":0,
"unknownMalwareConfidenceMatches":0,
"alertsGenerated":0,
"filesBlocked":0,
"connectionsReset":0
}
},
{
"engine":"Flash Analysis Engine",
"values":{
"filesSubmitted":0,
"filesIgnored":0,
"filesProcessed":0,
"atdFilesDroppedUnderLoad":0,
"atdStaticAnalysis":0,
"atdDynamicAnalysis":0,
"atdCacheReferences":0,
"cleanFiles":0,
"veryHighMalwareConfidenceMatches":0,
"highMalwareConfidenceMatches":0,
"mediumMalwareConfidenceMatches":0,
"lowMalwareConfidenceMatches":0,
"veryLowMalwareConfidenceMatches":0,
"unknownMalwareConfidenceMatches":0,
"alertsGenerated":0,
"filesBlocked":0,
"connectionsReset":0
}
}
]
}
Error Information
Following error code is returned by this URL:
No | HTTP Error Code | SDK API errorId | SDK API errorMessage |
|---|---|---|---|
1 | 404 | 1106 | Invalid Sensor: When the device id given is not valid |