request wildfire sample redistribution
Description
Redistribute samples
from the local WildFire appliance cluster node to another cluster
node while optionally retaining samples on the local node.
Hierarchy Location
request system
Syntax
request {
wildfire {
sample {
redistribution {
keep-local-copy {no | yes};
serial-number <value>;
}
}
}
}
Options
* keep-local-copy—Keep
or do not keep a copy of the redistributed samples on the local
WildFire appliance node.
* serial-number—Serial
number of the node to which you redistribute samples.
Sample Output
Storage Nodes displays
the other node to which the local node redistributes samples. If
the local node is not redistributing samples, only one storage node
location displays. If the local node is redistributing samples, Storage
Nodes shows two storage node locations. The highlighted
output shows the two storage nodes that store samples (the local
node and the node to which the local node redistributes samples)
and verifies that sample redistribution is occurring.
admin@WF-500> show wildfire global sample-analysis
Last Created 100 Malicious Samples
+----------------------------------------------------------------------+
| SHA256 | Finish Date | Create Date | Malicious |
+----------------------------------------------------------------------+
| <HASH VALUE> | 2017-03-24 17:27:40 | 2017-03-24 15:41:47 | Yes |
| <HASH VALUE> | 2017-03-24 17:26:46 | 2017-03-24 15:41:45 | Yes |
| <HASH VALUE> | 2017-03-24 17:26:54 | 2017-03-24 15:41:45 | Yes |
| <HASH VALUE> | 2017-03-24 17:25:12 | 2017-03-24 15:41:44 | Yes |
| <HASH VALUE> | 2017-03-24 17:24:28 | 2017-03-24 15:41:44 | Yes |
| <HASH VALUE> | 2017-03-24 17:23:58 | 2017-03-24 15:41:44 | Yes |
| <HASH VALUE> | 2017-03-24 17:26:52 | 2017-03-24 14:55:23 | Yes |
| <HASH VALUE> | 2017-03-24 17:23:32 | 2017-03-24 14:55:23 | Yes |
| <HASH VALUE> | 2017-03-24 17:24:58 | 2017-03-24 14:55:23 | Yes |
| <HASH VALUE> | 2017-03-24 17:22:02 | 2017-03-24 14:55:23 | Yes |
+----------------------------------------------------------------------+
+--------------------------------------------------------------------+
| Storage Nodes | Analysis Nodes | Status | File Type |
+--------------------------------------------------------------------+
| 0907:ld2_2,065:ld2_2 | qa116 | Notify Finish | Java JAR |
| 0097:ld2_2,004:ld2_2 | qa117 | Notify Finish | Java Class |
| 0524:ld2_2,006:ld2_2 | qa117 | Notify Finish | Java Class |
| 0656:ld2_2,524:ld2_2 | qa117 | Notify Finish | Java Class |
| 0024:ld2_2,056:ld2_2 | qa117 | Notify Finish | DLL |
| 0324:ld2_2,006:ld2_2 | qa117 | Notify Finish | Java JAR |
| 0682:ld2_2,006:ld2_2 | qa116 | Notify Finish | Java JAR |
| 0092:ld2_2,016:ld2_2 | qa116 | Notify Finish | DLL |
| 0682:ld2_2,002:ld2_2 | qa116 | Notify Finish | DLL |
| 0056:ld2_2,824:ld2_2 | qa117 | Notify Finish | DLL |
+--------------------------------------------------------------------*
lines 1-10
Required Privilege Level
superuser, deviceadmin