The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Enable the Trend analysis and custom resource configuration

Prev Next

The engine used for trend analysis reporting is disabled by default. As the number of alerts in your database continues to grow, this engine may consume valuable processing cycles on your Manager server. The trend engine is required to maintain the tables that provide immediate trend analysis results for all of your database alerts. Without this engine, trend reports could take from several seconds to minutes to produce results. You may choose to disable this service if you are not currently interested in running trend analysis reports.

You can filter report information by assigning a specific resource, namely a single device, interface, or sub-interface for finer trend analysis.

Steps:

  1. Click the Analysis tab from the Home page.

  2. Select Event Reporting → Traditional Reports → Trend Analysis from the list of IPS Events.

  3. Click Configure.

  4. Do one of the following:

    • To disable the trend analysis engine, select No and click Save.

    • To assign a resource finer than an entire device, do the following:

      1. Click Add.

      2. Select the Admin Domain from the drop-down list in which the device you want to use resides.

        Note

        The admin domain selected in the left pane has no impact on the reports generated. The Admin Domain drop-down list is explicitly to filter the reports that are generated.

      3. Select a Sensor you want to include in the trend analysis.

      4. Select an Interface on the device. The Interface field may also include any sub-interface resources.

        Note

        You cannot select just a device resource. When you select a device, you are also selecting an interface resource.

    • Click Save. Your added resource appears in the "Trend Resource" pane as well as in the Trend Analysis report's Resource field.

      Note

      At any time you can select a configured resource from the "Trend Resource" pane and click Delete to exclude a resource from trend analysis. However, you cannot delete a device resource.

  5. Click Back to exit the Trend Analysis configuration page and return to the Trend Analysis report page.