The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Displaying IPS events and alerts (web UI)

Prev Next

This topic describes how to display the results of IPS detection and blocking activities performed by your IPS platform.

When the IPS-enabled rules engine matches a traffic flow to an active IPS rule, the platform generates an IPS event. For client-targeted IPS events that correlate with MVX-verified malware alerts, the platform triggers IPS alerts.

  • IPS events and IPS alerts are listed in the IPS Events page.

  • IPS alerts for client-targeted attacks are listed in both the Hosts tab and the Alerts tab.

  • IPS event statistics are reflected in two panels in the Dashboard.

  • From the Reports page, you can generate IPS-specific reports that contain summaries and detailed information about HTTP-based malware alerts, IPS alerts, and IPS events.

  • If you configured FireEye event notifications for IPS events, notifications are sent using the notification methods you configured.

You can use this information to determine how to customize your configuration of IPS packet processing.

Prerequisites

Before you begin analyzing initial IPS results, perform the following prerequisite tasks:

  • Log in to the appliance Web UI as Monitor, Analyst, or Admin.

  • (Recommended) Configure notifications of IPS events.

  • (Optional) Disable or re-enable IPS block mode if needed.

  • Apply default IPS policies to monitoring interfaces.

  • Wait several minutes for IPS event detection to begin to appear in the Web UI.

Procedure

To display IPS data:

  1. Choose IPS > IPS Events to verify that the IPS rules you activated are detecting IPS events.

    scap_ips_events.png

    The IPS Events page lists all IPS events detected by the platform within the time frame specified by using the calendar icon (ctrl_ips_IPS_Events_date_range_icon.png).

    If an entry represents one or more MVX-correlated IPS events (IPS alerts), the following badge appears in the Badges column:

    icon_badge_mvx.png

    If an entry represents one or more IPS events that have been verified to be non-malicious, the following badge appears in the Badges column:

    icon_badge_not-an-attack.png

    For more information, see About the IPS events page.

  2. To display a list of all alerts triggered on the appliance, select the Alerts page. Different pages list malware alerts (MVX-verified malware events), IPS alerts (MVX-correlated IPS events), and callback events.

    Hosts

    This page lists all malware alerts and IPS alerts, grouped by victim IP address and attack rule name. Multiple alerts associated with the same victim and signature rule are combined in a single entry. If an entry represents one or more IPS alerts, the following badge appears in the IPS column:

    icon_badge_ips.png

    For more information, see Alerts grouped by victim IP addresses.

    Alerts

    This page lists all malware alerts and IPS alerts, grouped by attack rule name only. Multiple alerts associated with the same signature rule are combined in a single entry. If an entry represents one or more IPS alerts, the following badge appears in the IPS column:

    icon_badge_ips.png

    For more information, see Alerts grouped by attack rule names.

    Callback Activity

    This page lists all callback events associated with a malware alert. For more information, see Alerts grouped by CnC servers contacted.

  3. For a high-level view of the IPS-specific threat intelligence gathered by the IPS platform, select the Dashboard page and view the following Dashboard panels:

    What's Happening

    For IPS platforms, this panel includes the count of IPS alerts detected by the appliance, provided that the value is not zero.

    scap_ips_dashboard_3_Whats_Happening.png

    Click MVX Correlated IPS Events to open the IPS Events page filtered to display only IPS alerts.

    IPS Trend

    For IPS platforms, this panel contains a two-series line graph that plots the number of IPS alerts and IPS critical events detected by the appliance over the past month, week, or day of IPS analysis.

    scap_ips_dashboard_9_IPS_Trend.png

    For more information, see IPS information in the dashboard.

  4. To generate IPS-specific reports, select the Reports page. The following reports are available on IPS-enabled platforms only:

    IPS Executive Summary

    Provides a high-level view of IPS statistics.

    IPS Policy Configuration Summary

    Identifies IPS policies active on monitoring interfaces; counts the active IPS rules and excluded IPS rules at each active monitoring interface; and summarizes the characteristics of the active IPS rules at each active monitoring interface.

    IPS Policy Configuration Details

    Provides the same information as the IPS Policy Configuration Summary, but also lists the active rules, excluded rules, and included rules at each monitoring interface.

    IPS Top N Attacks

    Extracts traffic analysis statistics about IPS rules used to detect suspicious events.

    IPS Top N Attackers

    Extracts traffic analysis statistics about hosts that sent suspicious traffic detected by IPS rules.

    IPS Top N Victims

    Extracts traffic analysis statistics about hosts that received suspicious traffic detected by IPS rules.

    IPS Top N MVX‑Correlated

    Provides the Top N Attacks, Top N Attackers, and Top N Victims reports.

    For more information, see IPS reports.

  5. If you disabled IPS blocking mode while evaluating the fit of IPS rules to your environment, be sure to re‑enable IPS blocking mode after you finish customizing the configuration of IPS packet processing by your platform.