You can add a scheduled report template which enables you to schedule a new report that generates automatically and emailed regularly. You can schedule a report for any of the IPS Events and Configuration Reports. When you schedule a report, you need to specify the parameters for the report (Example: Admin Domain, Sensor).
To schedule a report:
Steps:
Click the Manager icon from the Home page.
Select <Admin Domain Name> → Reporting → Report Automation → Automation Settings.
The Automation Settings page is displayed.
Click
.The Add an Automated Report page is displayed.
The Enable? field is enabled by default.
Select the Report Category — IPS Events or Configuration Reports.
Select the Report Type. Based on this selection, the template fields change to fit the elements of the selected report. Only those fields that are common to all report types are described in detail in this section. Template fields that appear for a specific report type selection are summarized.
Traditional-IPS Event reports
Big Movers report
Executive Summary report
Reconnaissance Attacks report
Top N Attacks report
Trend Analysis report
User Defined report
Traditional-Configuration reports
Attack Set Profile report
Device Summary Report
Faults report
Firewall Policy Definitions report
IPS Policy Assignment report
IPS Policy Details report
IPS Sensor report
Licenses
Performance Monitoring - Admin Domain Configuration report
Performance Monitoring - Sensor Configuration report
QoS Policy
Scanning Exceptions
User Activity report
Version Summary
For Report Category selected as Configuration Reports -
Type a Template Name.
Type a Description that summarizes the report. The maximum length is 254 characters. This is for future reference.
Choose a Report Frequency as either Hourly, Daily, Weekly or Monthly. The default is Weekly.
Select Report Format. The options are PDF Portrait, PDF Landscape, Save as HTML, and Save as CSV.
Below is the summary of the template fields that appear when a specific Report Type is selected:
Configuration Report - Report Type
Available fields for configuration
Attack Set Profile
Select a required Attack Set Profile
Device Summary
Select the required Admin Domain
Faults
Fields available for configuration are Fault Source, Admin Domain (with an option to include child admin domains), Sensor (all devices or a single device), Fault Severity, Fault State, Organized By, Select Faults to Display (date and time selection for faults as per Report Frequency selected)
Firewall Policy Definitions
Select the required Admin Domain and Firewall Policy Name
IPS Policy Assignments
Select the required Sensor(s). Tick the required checkboxes for Customized Attacks, Exploit/DoS Policy, IPS Policy Detail, DoS Detail, Attack Set Profile Detail, and Recon Attacks.
IPS Policy Details
Select the required Policies and select the required checkboxes for IPS Policy Detail, DoS Detail, Attack Set Profile Detail, Customized Attacksand Recon Attacks.
IPS Sensor
Select the required Sensor(s) and select the required checkboxes for Device Information, TCP/IP Settings, Alerting Options, TACACS+ Authentication Settings, Quarantine Information, Performance Monitoring, TIE Integration, Port Configuration, Non-Standard Ports, L2 Switch & SSL Configuration, Exception Details, CLI Auditing, Interface Configuration, NMS Configuration, HTTP Response Settings, Layer 7 Data Collection, and Trellix Intelligent Sandbox Integration.
Performance Monitoring - Admin Domain Configuration
Select the required Admin Domain and select the required checkboxes for Metrics, Thresholds, and Display.
Performance Monitoring - Sensor Configuration
Select the required Sensor(s) and select the required checkboxes for Metrics, and Thresholds.
QoS Policy
Select the required Admin Domain and Firewall Policy Name
Scanning Exceptions
Select the required Sensor(s) and select the required checkboxes for VLAN Exceptions, and TCP Exceptions, and UDP Exceptions.
User Activity
Fields available for configuration are Admin Domain (with an option to include child admin domain audit data), Select User(s) to Audit, Audit Categories (with an option to select time and day of the week for weekly reports), Select messages to Display (day range), Show Details, and Show messages (number of messages).
Version Summary and Licenses
N/A
For Report Category selected as IPS Events -
Type a Template Name.
Type a Description that summarizes the report. This is for future reference.
Choose a Report Frequency as either Hourly, Daily, Weekly or Monthly. The default is Weekly.
Select Report Format. The options are PDF Portrait, PDF Landscape, Save as HTML, and Save as CSV.
Note
The PDF option appears disabled if you had selected the Report Frequency as Monthly.
Below is the summary of the template fields that appear when a specific Report Type is selected:
IPS Events - Report Type
Available fields for configuration
Big Movers
Select the required Admin Domain (with an option to include child admin domains), Sensor (all devices or a single device), Alert Severity, Ranking Basis, Direction (directions for alert display), Maximum Movers (value of maximum occurred alerts to be displayed), and Comparison Intervals (time period in days).
Executive Summary
Fields available for configuration are Report Start (day and time), Alert Time Range (day or week), Admin Domain (with an option to include child admin domains), Sensor (all devices or a single device), Alert Severity, Relevance, Show only Block attacks? (yes/no), Alert State, NSLookUp, Get Summary of (number of top alerts to be displayed, default value is 10), Sort by Attack Severity, and Optional Data.
Reconnaissance Attacks
Fields available for configuration are Report Start (day and time), Alert Time Range (day or week), Admin Domain (with an option to include child admin domains), Sensor (all devices or a single device), Alert Severity, and Alert State.
Top N Attacks
Fields available for configuration are Report Start (day and time), Alert Time Range (day or week), Admin Domain (with an option to include child admin domains), Sensor (all devices or a single device), Alert Severity, Show only Block attacks? (yes/no), Alert State, Desired Number('N') of Attack Instances (Default number is 10), NSLookUp, Sort by Attack Severity, Report Content (table and/or chart), Report Format (bar chart or pie chart).
Trend Analysis
Fields available for configuration are Report Start (day and time), Resource (Admin domain and Sensor), Trend Items(s), Trend report Interval (Hour or day) Trend Report Period, and Report Content (table and/or chart).
User Defined
Fields available for configuration are Report Start (day and time), Select Alerts to Display (day or week), Admin Domain (with an option to include child admin domains), Sensor (all devices or a single device), Interface(s), Detection Mechanism, Application Protocol,Attack Category, Attack Sub-category(s), Detection Mechanism, Application Protocol, Source IP address and Port Number, Destination IP Address and Port Number, Direction of Alert,Alert Severity, Relevance, Select Alert/Attack Type, Alert State, Field of Interest, and Organized By.
Click Next. The Select Recipients page appears.
Select the recipients from the grid.
Click Finish.