This procedure describes how to view alerts for Infection Match and Malware Callback events with blocked traffic.
Prerequisites
Monitor, Analyst, Operator, or Admin access to the Network Security appliance Web UI.
Go to the Alerts > Alerts > Hosts page or the Alerts > Alerts > Alerts page. Alerts for blocked traffic are marked with a Blocked badge in the Badges column.
Note
To list all Blocked alerts together, you can filter or sort the list of alerts on the Badges column.
After an Infection Match or a Malware Callback event is detected, there can be a delay of up to 30 seconds before the appliance determines whether traffic was blocked and the Web UI displays the Blocked badge. By default, the blocked-by-proxy detection feature waits up to 10 seconds for confirmation that the event was blocked by the Web proxy.
To display alert details, expand the entry by clicking the icon in the first column of the alert entry. The detailed information includes a Blocking Action message that shows that the traffic was blocked by the Web proxy. For more information, see Badge for Blocked Traffic Events.