The Alerts > Alerts > Alerts page of a Network Security appliance lists malware alerts (MVX-verified malware events) and associated callback activity. If IPS is enabled on the appliance, the page also lists IPS alerts (MVX-correlated IPS events). The page lists the alerts organized by attack (source IP address, target IP address, and attack rule name). Multiple alerts associated with the same victim and signature rule are combined in a single row, called an alert grouping.
If the appliance has obtained threat intelligence for an alert, a Threat Info badge appears in the Badges column.
For more information, see About ATI .
Note
For managed Network Security appliances, ATI badges and ATI information are visible from the Central Management System appliance Web UI only.
Prerequisites
Log in to the Network Security Web UI with a user account that is associated with the Analyst, Operator, or Admin role.
Verify that the appliance is enabled for ATI. Use the show ati status CLI command.
In the Web UI, open the Alerts > Alerts > Alerts page.
Choose the ATI alert that you want to view. To locate an alert in the list, you can modify the display in any of the following ways:
Change the time duration displayed in the list.
Sort the list on a column by clicking the column name.
Filter the list on any column by clicking the search icon and then entering or selecting the filter match criteria in the text box. You can filter the Badges column for Threat Info badges.
Click the Threat Info badge for the alert you want to view.
If the alert grouping represents more than one ATI alert, you see a filtered list of individual ATI alerts. Clicking an alert displays the Alert Details page, which provides threat intelligence for that alert. Anchors on the left expand links on the detail page for further information (e.g., Callback communication from infected host). For a detailed description of the threat intelligence information, see ATI badges in the Web UI .