The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Generate Faults reports

Prev Next

The Faults Report enables you to see the details of Sensor and Manager faults that have occurred in the past. Reports can be generated based on the fault name, its creation time, its fault severity, or by the Sensor ID.

To generate the report, do the following:

Steps:

  1. Click the Manager tab from the Manager Home page.

  2. Select <Admin Domain Name> → Reporting → Configuration Reports → Faults.

  3. Specify the following to narrow down the scope of your report:

    • Fault Source — Select Sensor and/or Manager to find faults on your Sensor and/or Manager, respectively.

    • Admin Domain — Select an admin domain on which to run the report. This is enabled only if the selected Fault Source is Sensor.

      Note

      The admin domain selected in the left pane has no impact on the reports generated. The Admin Domain drop-down list is explicitly to filter the reports that are generated.

    • Include Child Admin Domains — If you have selected Include Child Admin Domains, Sensors in the child admin domains of the selected admin domain are also displayed. This is enabled only if the selected Fault Source as Sensor.

    • Sensor — Select one or all devices on which to run the report.

    • Fault Severity — Select one or more of the following:

      • Informational

      • Warning

      • Error

      • Critical

    • Fault State — Select one of the following from the drop-down menu:

      • All Faults

      • Active Faults

      • Deleted Faults

      • Acknowledged Faults

    • Select the Duration — Select from one of the following duration from the drop-down list:

      • Last 5 minutes

      • Last 1 hour

      • Last 6 hours

      • Last 12 hours

      • Last 24 hours

      • Last 48 hours

      • Last 7 days

      • Last 14 days

      • Custom time period —Enables you to select and view specific faults between a Start Time and End Time (you can specify both the date and time and click Apply)

        Note

        Faults with creation date previous to the Start Time may get displayed too, implying that the particular fault had occurred before the begin data and re-occurred again between the Start Time and End Time.

    • Select the Report Format

    • Organized by — Specify how you want the information to be organized in the report. Choices are Severity, Fault Name, Sensor, or Create Time. For example, if you choose Severity, then the information is organized by fault name in the reverse alphabetical order. Create Time is the fault generation time.

  4. Click Run to generate the report.

    Note

    Only 5000 faults can be processed for a report. If more than 5000 faults are involved, a note is displayed recommending you to narrow down the scope of your report.

    The field descriptions under the Fault Log details section of this report are as follows:

    Field Name

    Description

    Time

    The time at which the fault was generated.

    Duration

    The length of time the fault lasted. For example, in the case of a performance fault, this is the number of minutes between when the performance first went over its threshold and when it subsequently fell below its reset threshold.

    Source

    The source of the fault.

    Criticality

    Specifies the severity level of the fault.

    Name

    Specifies the name of the fault.

    Description

    A detailed description of the fault.

    Type

    The type of fault.

    Acknowledged

    Indicates whether the fault is acknowledged or not.

    Deleted

    Indicates whether the fault is deleted or not.

    Last Updated

    The time at which the fault was last modified. This time stamp gets updated when the fault is acknowledged.