Exosphere

Download 6
Last updated Nov 9, 2024

exosp-av-alerts

Fetch antivirus alerts for specified date range from Exosphere service.

exosp-av-alerts [profile=PROFILE] [duration=NUM{mon|w|d|h|m|s}] [from=yyyyMMddHHmmss] [to=yyyyMMddHHmmss] [order=ORDER]
profile=PROFILE
Connect profile code of Exosphere
duration=NUM{mon|w|d|h|m|s}
Scan only recent data. You should use s(second), m(minute), h(hour), d(day), mon(month) time unit. For example, 10s means data from 10 seconds earlier.
from=yyyyMMddHHmmss
Start time of range. yyyyMMddHHmmss format. If you omit time part, it will be padded by zero.
to=yyyyMMddHHmmss
End time of range. yyyyMMddHHmmss format. If you omit time part, it will be padded by zero.
order=ORDER
asc or desc.

Output Fields

FieldTypeNameDescription
_timeDateEvent time
profileStringConnect profileExosphere connect profile code
os_nameStringOS namee.g. windows, macos
hostnameStringhostnamee.g. Scott's MacBook Pro
dept_nameStringdept_namee.g. HR
emp_nameStringemp_namee.g. Scott
userStringusere.g. scott
inspection_typeStringInspection typee.g. MN(Manual), RS(Reserved), RT(Realtime)
categoryStringcategorye.g. virus, program
signatureStringsignaturee.g. Eicar-Test-Signature
actionStringactione.g. quarantined, disinfected, skipped, none
resultStringresulte.g. success, fail
file_nameStringfile_namee.g. eicarcom2.zip
sha256Stringsha256
file_pathStringfile_pathe.g. /path/to/eicarcom2.zip
dept_pathStringdept_pathe.g. Logpresso > HR