The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Generate Applications Custom user defined reports

Prev Next

Prerequisites:

This section assumes that you are familiar with terms related to Application Identification and how this feature works.

Make sure you have enabled Application Identification on the required Monitoring ports for the time period that you want to run the report.

Follow this procedure to generate Applications Custom user defined report.

Steps:

  1. In the Manager, select Analysis → Event Reporting → Custom Reports.

  2. Click New and select Application Data.

  3. Specify how you want the data to be consolidated in the report (Hourly |Daily | Weekly | Monthly).

    Consider that you select weekly, and generate the report for a two weeks' time period, and FTP is one of the applications detected. Then, the details for FTP is shown separately for each of those two weeks. Similarly, the details are shown for all the detected applications during those two weeks.

  4. To view the report in a tabular format, select Table as the Display Option and click Next.

    1. Select Application Name, Category Name, or Risk as the first column.

    2. Select Attack Count, Bandwidth Usage, or Connection Count as the second column.

    3. If required select Start Time as the third column.

    4. Click Next and go to step 7.

  5. To view the details in a bar chart and a tabular format, Select Bar Chart as the Display Option and click Next.

    1. Select Application Name, Category Name, or Risk as the Bar label.

    2. Select Attack Count, Bandwidth Usage, or Connection Count as the Bar value.

    3. Click Next and go to step 7.

  6. To view the details in a pie chart and a tabular format, Select Pie Chart as the Display Option and click Next.

    1. Select Application Name, Category Name, or Risk as the Pie slice label.

    2. Select Attack Count, Bandwidth Usage, or Connection Count as the Pie slice value.

    3. Click Next.

  7. In the Data Filter section, click on the right arrow next to the Admin Domain and select the required Admin Domain name from the Value drop-down.

    The Value drop-down for Admin Domain lists only those domains that have Sensors assigned to them. Admin domains that have no Sensors but only dedicated Monitoring ports are not listed.

  8. To include data only from specific Sensors of the selected Admin Domain, click on the right arrow next to Sensor. To include data from all the Sensors of the selected Admin Domains, you do not need to add the Sensor row.

    Note

    The admin domain selected in the left pane has no impact on the reports generated. The admin domain data filter selected is explicitly to filter the reports that are generated.

  9. Select the comparison value (equals or does not equal) and the Sensor name.

  10. Add another row for Sensor, if required.

  11. Click Next.

  12. Select one of the Date Options (either query for the day or between two dates or for a selected period in the past). Select the report format (HTML, PDF Portrait, PDF Landscape, Save as CSV or Save as HTML).

  13. Run the report immediately or save it for later use.

    If you save the report, it is listed along with the other saved Custom reports. You can run it like how you would run any of the Custom reports.