Cisco Cisco Firepower Management Center 4000
34-12
FireSIGHT System User Guide
Chapter 34 Analyzing Malware and File Activity
Working with File Events
For detailed information on search syntax, including using objects in searches, see
.
Special Search Syntax for File Events
To supplement the general search syntax listed above, the following table describes some special search
syntax for file events.
syntax for file events.
To search for file events:
Access:
Admin/Any Security Analyst
Step 1
Select
Analysis > Search
.
The Search page appears.
Step 2
From the
Table
drop-down list, select
File Events
.
The page reloads with the appropriate constraints.
Step 3
Optionally, if you want to save the search, enter a name for the search in the
Name
field.
If you do not enter a name, one is created automatically when you save the search.
Step 4
Enter your search criteria in the appropriate fields.
See the
table for information on the fields in the file events table.
Step 5
If you want to save the search so that other users can access it, clear the
Save As Private
check box.
Otherwise, leave the check box selected to save the search as private.
If you want to use the search as a data restriction for a custom user role, you must save it as a private
search.
search.
Step 6
You have the following options:
•
Click
Search
to start the search.
Table 34-3
File Event Special Search Syntax
Search Criterion
Special Syntax
Sending/Receiving Continent The system returns all events where either the
Sending Continent
or the
Receiving Continent
matches the continent you specify.
Sending/Receiving Country
The system returns all events where either the
Sending Country
or the
Receiving Country
matches the country you specify.
Sending/Receiving IP
The system returns all events where either the
Sending IP
or the
Receiving
IP
matches the IP address you specify.
URI or Message
The system performs a partial match, that is, you can search for all or
part of the field contents without using asterisks.
part of the field contents without using asterisks.
File Storage
Specify one or more of the following:
•
Stored
- returns all events where the associated file is currently
stored
•
Stored in connection
- returns all events where the system
captured and stored the associated file, regardless of whether the
associated file is currently stored
associated file is currently stored
•
Failed
- returns all events where the system failed to store the
associated file