The Custom Default report options are available as follows:
Report Name | Description |
|---|---|
Default - Telemetry (Insights Security Posture) | The telemetry information sent by the Manager to the Trellix Insights when Insights integration is enabled.
|
Default - Telemetry (IPS/Insights) | The information sent by the Manager to the Trellix IPS product team and Trellix Insights team when telemetry is enabled |
Default - Telemetry (Trellix) | The information sent by the Manager to the Trellix corporate team when telemetry is enabled |
Default - Telemetry (Trellix - Titan F Telemetry Server) | The information sent by the Manager to the Titan F telemetry server when telemetry is enabled |
Applications-related reports
For any Applications-related report to show data, you must enable Application Identification on the required Monitoring ports for the time period that you query. For example, if you want to run the Top 10 Application Categories by Attack Count report for the traffic monitored between 9 am and 10 am today, you must have enabled Application Identification on the corresponding monitoring ports between 9 am and 10 am today based on the Manager server's clock.
Report Name | Description |
|---|---|
Default - Top 10 Application Categories by Attack Count | Run this report to view the top 10 Categories based on the attacks generated per category. Like other Custom reports, this too displays information in graphical and tabular formats. The following are the information that you can find in this report:
|
Default - Top 10 Application Categories by Bandwidth Usage | This report is similar to the Top 10 Application Categories by attack count except that the details are based on the bandwidth consumed. |
Default - Top 10 Application Categories by Connection Count | This report is similar to the Top 10 Application Categories by attack count except that the details are based on the number of connections or flows. |
Default - Top 10 Applications by Attack Count | Run this report to view the top 10 Applications based on the number of attacks that each application was involved. The following are the information that you can find in this report:
|
Default - Top 10 Applications by Bandwidth Usage for All Risk Levels | This report is similar to the Top 10 Applications by attack count except that it is based on the bandwidth consumed by each application. |
Default - Top 10 Applications by Bandwidth Usage for Each Risk Level | This report provides the top 10 applications in each risk category based on the bandwidth consumed per application. That is, it lists the top 10 high-risk applications based on bandwidth consumed by each of those applications. Similarly, it lists the top 10 medium and low-risk applications in separate tables. |
Default - Top 10 Applications by Connection Count | This report is similar to the Top 10 Applications by attack count except that it is based on the number of connections per application. |
Note
For the applications-related reports to show data, you must enable Application Identification.
The Default Custom reports show information from all the Sensors for which you have enabled Application Identification. To view the details from specific Sensors, you can generate a Custom duplicate report or a Custom user defined report.
Report Name | Description |
|---|---|
Default - High Device TCP / UDP Flow Usage | Status of TCP/UDP flow utilization |
Default - High Device Throughput Usage | Status of Sensor throughput utilization threshold |