To display detailed information about a group of IPS brute-force events listed in the IPS Events page, click the entry's expand icon (
) next to the check box.
The following example shows the drill-down view of a one-to-one FTP brute-force event entry.

The following table describes the brute force-specific fields in the drill-down view of an IPS brute-force event entry.
Field | Description |
|---|---|
IP Protocol | TCP or UDP |
Victim Port | Port number last attacked on the most recent victim. |
Victim IP | IP address of the victim. |
Brute force events | |
Number of failed login | Number of failed login attempts detected for all events in the entry. |
Victim IPs | IP addresses of the most recent victims (up to 5 addresses). |
Attacker IPs | IP addresses of the most recent attackers (up to 5 addresses). |
Total Victim IP Count | Number of victims identified. NOTE: This value might be an estimate. |
Total Attacker IP Count | Number of attackers identified. NOTE: This value might be an estimate. |
Note
For most brute-force events, some statistics are estimated values rather than exact counts. The following values are provided as reference information only:
Victim IP Count
Attacker IP Count
Brute-force analysis is a resource-intensive process. When it is necessary to conserve resources, the analysis process does not record all IP addresses involved in the attack. In this case, the process must estimate the count of IP addresses or port numbers. To estimate the count, the process compares the current IP address or port count with the most recent IP addresses or port counts in cache memory.