The Faults Report enables you to see the details of Sensor and Manager faults that have occurred in the past. Reports can be generated based on the fault name, its creation time, its fault severity, or by the Sensor ID.
To generate a Faults report, do the following:
Task
- Click the Manager tab from the Manager Home page.
- Select <Admin Domain Name> → Reporting → Configuration Reports → Faults.
-
Specify the following to narrow down the scope of your report:
- Fault Source — Select Sensor and/or Trellix IPS Manager to find faults on your Sensor and/or Manager, respectively.
-
Admin Domain — Select an admin domain on which to run the report. This is enabled only if the selected
Fault Source is
Sensor.
Note
The admin domain selected in the left pane has no impact on the reports generated. The Admin Domain drop-down list is explicitly to filter the reports that are generated.
- Include Child Admin Domains — If you have selected Include Child Admin Domains, Sensors in the child admin domains of the selected admin domain are also displayed. This is enabled only if the selected Fault Source as Sensor.
- Sensor — Select one or all devices on which to run the report.
-
Fault Severity — Select one or more of the following:
- Informational
- Warning
- Error
- Critical
-
Fault State — Select one of the following:
- All Faults
- Active Faults
- Deleted Faults
- Acknowledged Faults
- Faults — Select from one of the following time options:
- Select Faults for this day (yyyy/mm/dd) — Displays faults for a selected day.
- Select Faults between these dates (yyyy/mm/dd hh:mm:ss) — Displays faults between the Begin Date and the End Date.
- Select Faults in the past — Displays faults for the specified period and ending at the specified time. The default is the current time.
Note
Faults with creation date previous to the Begin date may get displayed too, implying that the particular fault had occurred before the begin data and re-occurred again between the Begin and End date.
-
Report Format — Select any of the following format for the report:
- HTML
- PDF Portrait
- PDF landscape
- Save as CSV
- Save as HTML
- Organized by — Specify how you want the information to be organized in the report. Choices are Severity, Fault Name, Sensor, or Create Time. For example, if you choose Severity, then the information is organized by fault name in the reverse alphabetical order. Create Time is the fault generation time.
-
Click
Run Report to generate the report.
Note
Only 5000 faults can be processed for a report. If more than 5000 faults are involved, a note is displayed recommending you to narrow down the scope of your report.
The field descriptions in this report are as follows:Field Name Description Time The time at which the fault was generated. Duration The length of time the fault lasted. For example, in the case of a performance fault, this is the number of minutes between when the performance first went over its threshold and when it subsequently fell below its reset threshold. Source The source of the fault. Criticality Specifies the severity level of the fault. Undefined Specifies the name of the fault that is undefined. Description A detailed description of the fault. Type The type of fault. Acknowledged Indicates whether the fault is acknowledged or not. Deleted Indicates whether the fault is deleted or not. Last Updated The time at which the fault was last modified. This time stamp gets updated when the fault is acknowledged.