The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Custom Default reports

Prev Next

The Custom Default report options are available as follows:

Telemetry reports

Report Name

Description

Default - Telemetry (Insights Security Posture)

The telemetry information sent by the Manager to the Trellix Insights when Insights integration is enabled.

Note

This information is used to derive the security posture score on Trellix Insights.

Default - Telemetry (IPS/Insights)

The information sent by the Manager to the Trellix IPS product team and Trellix Insights team when telemetry is enabled

Default - Telemetry (Trellix)

The information sent by the Manager to the Trellix corporate team when telemetry is enabled

Default - Telemetry (Trellix - Titan F Telemetry Server)

The information sent by the Manager to the Titan F telemetry server when telemetry is enabled



Applications-related reports

For any Applications-related report to show data, you must enable Application Identification on the required Monitoring ports for the time period that you query. For example, if you want to run the Top 10 Application Categories by Attack Count report for the traffic monitored between 9 am and 10 am today, you must have enabled Application Identification on the corresponding monitoring ports between 9 am and 10 am today based on the Manager server's clock.

Reports and Descriptions

Report Name

Description

Default - Top 10 Application Categories by Attack Count

Run this report to view the top 10 Categories based on the attacks generated per category. Like other Custom reports, this too displays information in graphical and tabular formats. The following are the information that you can find in this report:

  • For each of the top 10 categories, the bandwidth consumed, the number of flows, and the number of attacks generated per category.

  • The applications detected for each of the top 10 categories. For example, if web mail is one of the top 10 categories, it lists all the web mail applications that were detected. If an application belongs to multiple categories within the top 10, it is listed under each of those categories.

  • For each application, the bandwidth consumed, the number of flows, and the number of attacks generated.

Default - Top 10 Application Categories by Bandwidth Usage

This report is similar to the Top 10 Application Categories by attack count except that the details are based on the bandwidth consumed.

Default - Top 10 Application Categories by Connection Count

This report is similar to the Top 10 Application Categories by attack count except that the details are based on the number of connections or flows.

Default - Top 10 Applications by Attack Count

Run this report to view the top 10 Applications based on the number of attacks that each application was involved. The following are the information that you can find in this report:

  • Risk— Whether the application is high, medium, or low risk. Trellix ARC categorizes an application based on its vulnerability and the probability for it to deliver malware.

  • Bandwidth— The network bandwidth consumed by each application.

  • Connection count— The number of flows per application.

  • Attack count— The number of attacks that each application was involved. This report is sorted based on the attack count.

Default - Top 10 Applications by Bandwidth Usage for All Risk Levels

This report is similar to the Top 10 Applications by attack count except that it is based on the bandwidth consumed by each application.

Default - Top 10 Applications by Bandwidth Usage for Each Risk Level

This report provides the top 10 applications in each risk category based on the bandwidth consumed per application. That is, it lists the top 10 high-risk applications based on bandwidth consumed by each of those applications. Similarly, it lists the top 10 medium and low-risk applications in separate tables.

Default - Top 10 Applications by Connection Count

This report is similar to the Top 10 Applications by attack count except that it is based on the number of connections per application.



Note

For the applications-related reports to show data, you must enable Application Identification.

The Default Custom reports show information from all the Sensors for which you have enabled Application Identification. To view the details from specific Sensors, you can generate a Custom duplicate report or a Custom user defined report.

Device Performance - Hourly reports

Report Name

Description

Default - High Device TCP / UDP Flow Usage

Status of TCP/UDP flow utilization

Default - High Device Throughput Usage

Status of Sensor throughput utilization threshold