The Executive Summary report provides a summary view of alerts presented in a variety of tables, graphs, and charts. The alert information displayed results from filling out the report form by a narrowing set of parameters. The resulting report is a detailed snapshot of the most common parameters found in detected attacks.
Tip
This report is best used for displaying general alert information for the most common parameters in a presentation-style format.
Steps:
Select Analysis → Event Reporting → Traditional Reports.
The IPS Events page is displayed.
Click the Executive Summary link.
Fill in the following fields to narrow your report:
Admin Domain— Select the admin domain in which to view alerts.
Note
The admin domain selected in the left pane has no impact on the reports generated. The Admin Domain drop-down list is explicitly to filter the reports that are generated.
Sensor:
All Devices is checked by default. This displays information of all devices present at the selected Admin domain. To select your preference of devices, de-select All Devices and select the devices from the list box.
Include Child Admin Domains— Displays device information for child domains.
Attack Severity— Select one or more from the Informational, Low, Medium, or High severities, which relate to attack impact.
Relevance— Select one or more from the options, which is related to vulnerability relevancy.
Show Only Blocked Attacks?— Select Yes to view alerts that indicate attacks blocked by the device. The default for this field is No.
Alert State— Select one of the following to narrow the alerts:
View unacknowledged alerts— All unacknowledged alerts in the system for the specified time frame. If you have acknowledged alerts during your selected time range, this option suppresses those alerts.
View all alerts— (Default) both acknowledged and unacknowledged alerts for the specified time frame.
NSLookUp— This feature lists the host name with the IP address in the generated report. The host names are retrieved using either the Source IP address, Destination IP address or using Both.
For Attacks, choose one of the following time spans:
Select Attacks for this Day— Format is yyyy/mm/dd. Default is Manager server system date.
Select Attacks Between these Dates— Format is yyyy/mm/dd hh:mm:ss. Default Begin Date is "oldest alert detected time" and default End Date is Manager server system time.
Select Attacks in the past— Selects alerts from a point in the past relative to the current time. This time in the past can be months, weeks, days (Default), or hours. Type a time (yyyy/mm/dd hh:mm:ss) when the span of reporting time ends (default is Manager server system time).
Enter the number of most frequent attacks (Get summary of) to view. A valid entry is between 1 and 20.
Select the Sort By Attack Severity check box to include the attack severity.
Select Attack Count Per Relevance or Top N Source/Destination IP Pairs to include information about vulnerability relevance and source/destination IP addresses, respectively.
Select the Report Format.
Click Run Report.