Cisco Cisco Firepower Management Center 4000

Page of 1844
 
34-12
FireSIGHT System User Guide
 
Chapter 34      Analyzing Malware and File Activity 
  Working with File Events
For detailed information on search syntax, including using objects in searches, see 
.
Special Search Syntax for File Events
To supplement the general search syntax listed above, the following table describes some special search 
syntax for file events.
To search for file events:
Access: 
Admin/Any Security Analyst 
Step 1
Select 
Analysis > Search
.
The Search page appears.
Step 2
From the 
Table
 drop-down list, select 
File Events
.
The page reloads with the appropriate constraints.
Step 3
Optionally, if you want to save the search, enter a name for the search in the 
Name
 field.
If you do not enter a name, one is created automatically when you save the search.
Step 4
Enter your search criteria in the appropriate fields.
See the 
 table for information on the fields in the file events table.
Step 5
If you want to save the search so that other users can access it, clear the 
Save As Private
 check box. 
Otherwise, leave the check box selected to save the search as private.
If you want to use the search as a data restriction for a custom user role, you must save it as a private 
search.
Step 6
You have the following options:
  •
Click 
Search
 to start the search.
Table 34-3
File Event Special Search Syntax 
Search Criterion
Special Syntax
Sending/Receiving Continent The system returns all events where either the 
Sending Continent
 or the 
Receiving Continent
 matches the continent you specify.
Sending/Receiving Country
The system returns all events where either the 
Sending Country
 or the 
Receiving Country
 matches the country you specify.
Sending/Receiving IP
The system returns all events where either the 
Sending IP
 or the 
Receiving 
IP
 matches the IP address you specify.
URI or Message
The system performs a partial match, that is, you can search for all or 
part of the field contents without using asterisks.
File Storage
Specify one or more of the following:
  •
Stored
 - returns all events where the associated file is currently 
stored
  •
Stored in connection
 - returns all events where the system 
captured and stored the associated file, regardless of whether the 
associated file is currently stored
  •
Failed
 - returns all events where the system failed to store the 
associated file