The Alerts tab of the Network Security appliance list the results, grouped by alert, for web infections, infection matches, malware callbacks, and malware objects in ICAP traffic. You can drill down to identify the matched ICAP alerts that are detected as malicious for a malware event, grouped by alert. The total number of ICAP alert entries detected by the MVX engine are categorized and tracked on the Alerts tab.
An ICAP-enabled Network Security appliance supports four types of generated ICAP alerts: web infections, infection matches, malware callbacks, and malware objects.
ICAP alert entries are displayed on the Alerts tab. The default display lists entries in reverse chronological order and shows 20 results per page.
The following example displays the drill-down details of a particular malware callbackalert on ICAP traffic:

Prerequisites
Administrator, Monitor, or Analyst access to the Network Security appliance
Make sure that the third-party device settings are configured so that the device can act as an ICAP client. For details, see ICAP client configuration prerequisites.
You have enabled the ICAP service on the Network Security appliance. For details, see Enabling or disabling ICAP service using the Web UI or Enabling or disabling ICAP service using the CLI.
You have enabled the request modification mode or response modification mode. For details, see Enabling or disabling ICAP request and response modification modes using the Web UI or Enabling or disabling ICAP request and response modification modes using the CLI.
You have configured the ICAP service settings so that the Network Security appliance can run an ICAP server. For details, see Configuring the ICAP server port and SSL certificate using the Web UI or Configuring the ICAP server port and SSL certificate using the CLI.
Choose Alerts > Alerts > Alerts.
Choose the ICAP alert that you want to view.
To expand an entry, click the entry under any column heading.