The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Viewing Event Queries

Prev Next

Use the show analysis summary by command to query the information that are filtered based on the source IP address, destination IP address, MD5 checksum, or URL. This command searches for the details in the event results table based on the event type (os-change-anomaly, checksum-match, malware-callback, and so on). You can view malicious or nonmalicious objects or URLs from a specified or given source IP address or destination address.

When you enter this command on a Central Management System appliance, the ADD Product Series appliance displays details about the malware analysis summary on all managed ADD Product Series appliances based on your search queries.

Note

Event queries can be viewed only using the CLI.

Prerequisites

  • Administrator access to the ADD Product Series appliance.