The engine used for trend analysis reporting is disabled by default. As the number of alerts in your database continues to grow, this engine may consume valuable processing cycles on your Manager server. The trend engine is required to maintain the tables that provide immediate trend analysis results for all of your database alerts. Without this engine, trend reports could take from several seconds to minutes to produce results. You may choose to disable this service if you are not currently interested in running trend analysis reports.
You can filter report information by assigning a specific resource, namely a single device, interface, or sub-interface for finer trend analysis.
Steps:
Click the Analysis tab from the Home page.
Select Event Reporting → Traditional Reports → Trend Analysis from the list of IPS Events.
Click Configure.
Do one of the following:
To disable the trend analysis engine, select No and click Save.
To assign a resource finer than an entire device, do the following:
Click Add.
Select the Admin Domain from the drop-down list in which the device you want to use resides.
Note
The admin domain selected in the left pane has no impact on the reports generated. The Admin Domain drop-down list is explicitly to filter the reports that are generated.
Select a Sensor you want to include in the trend analysis.
Select an Interface on the device. The Interface field may also include any sub-interface resources.
Note
You cannot select just a device resource. When you select a device, you are also selecting an interface resource.
Click Save. Your added resource appears in the "Trend Resource" pane as well as in the Trend Analysis report's Resource field.
Note
At any time you can select a configured resource from the "Trend Resource" pane and click Delete to exclude a resource from trend analysis. However, you cannot delete a device resource.
Click Back to exit the Trend Analysis configuration page and return to the Trend Analysis report page.