The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Brute-force event entries in the IPS Events page

Prev Next

IPS brute-force events are listed in the IPS Events page only. You can identify IPS brute-force event entries by the Category value of brute_force.

The following example shows the IPS Events page filtered to show IPS brute-force events only. For more information, see Showing or hiding or brute-force events (Web UI).

scap_ips_events_brute-force_show_hide_option.png

Understanding IPS brute-force entries

Each brute-force event entry represents a group of one or more individual brute-force events that share the same victim or attacker IP address and brute-force attack subcategory. It is helpful to think of a brute-force event entry in terms of the number of victims and attackers it represents

One-to-Many

If the entry represents a single attacker conducting the same attack on multiple victims, the Victim IP field displays a green plus icon (icon_ips_ips-events-recon.png) next to the IP address of the most recent victim. Click the green plus icon (or the entry's expand icon next to the check box) to expand the entry. The drill-down view displays the IP addresses of the last five victims of the attack but the IP count and port range of the most recent victim only.

Many-to-One

If the entry represents multiple attackers conducting the same attack on a single victim, the Attacker IP field displays a green plus icon (icon_ips_ips-events-recon.png) next to the IP address of the most recent attacker. Click the green plus icon (or the entry's expand icon next to the check box) to expand the entry. The drill-down view displays the IP addresses of the last five attackers but the IP count and port range of the most recent attacker only.

One-to-One

If the entry represents one victim and one attacker, no green plus icon appears. The drill-down view does not list additional victims or attackers, though the number of attacks may be quite high.

How to find statistics for individual hosts within an aggregate entry

For any IPS brute-force event entry that represents either a many-to-one attack or a one-to-many attack, you might notice what appear to be extra one-to-one entries. The one-to-one entries seem to duplicate the information already aggregated into the multi-attacker or multi-victim event entry. The one-to-one entries are included to make available per-victim or per-attacker details.

For example, suppose the IPS Events list includes an entry that represents ten attackers and one victim (a 10: 1 entry) of Telnet brute-force attacks. When the entry is collapsed, you can see the IP address of the most recent attacker and the total number of attacks (in the # IPS Events field). When you expand the entry, you can see the IP addresses of four more recent attackers. Other statistics in the drill-down view, such as Total Connection Count and Victim IP Count, are aggregates of all ten attackers. Elsewhere in the IPS Events list, you will also see ten one-to-one entries that you might think are already accounted for in the 10: 1 entry. However, these entries contain individual statistics for each attacker.