The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Generate IPS Configuration Summary reports

Prev Next

The IPS Configuration Summary report provides a detailed view of the IPS configuration settings made by the user. This includes SNMP Forwarder Information, Alert Syslog Forwarder Information, Firewall Syslog Forwarder Information, Quarantine information, Network Objects, Quarantine Zones, Syslog Forwarding, Remediation Portal, IPS Settings and Quarantine. Information can be displayed for any selected admin domain in either .html, .pdf or .csv file formats.

To generate the report for an admin domain, do the following:

Steps:

  1. Click the Manager tab from the Manager Home page.

  2. Select <Admin Domain Name> → Reporting → Configuration Reports → IPS Configuration Summary.

  3. Select the required domain from the Admin Domain drop-down list.

    Note

    The admin domain selected in the left pane has no impact on the reports generated. The Admin Domain drop-down list is explicitly to filter the reports that are generated.

  4. Select the Report Format.

  5. Click Run.

    For the selected Admin Domain, IPS Configuration Summary report gives the following IPS configuration details:

    IPS Events SNMP Forwarder Information

    SNMP Forwarder Information specifies the server to which alert information will be sent from Manager. You can configure more than one SNMP server to where you want to send alert messages. The field details are described in the following table:

    Field Name

    Description

    IP Address

    IP address of the target SNMP server which can be IPv4 or IPv6 address.

    Destination Port Number

    The target server's SNMP listening port.

    SNMP Version

    Version of SNMP running on the target SNMP server. Version options are 1, 2c, Both 1 and 2c, and 3.

    SNMP Forwarder Information

    The SNMP server to where you want to send alert messages.

    Alert Syslog

    Alert Syslog Forwarder Information enables the forwarding of Trellix IPS alerts to a Syslog Server. The field detail is described in the following table:

    Field Name

    Description

    Syslog Forwarder Enabled

    Syslog forwarder has been enabled or disabled.

    Alert Syslog Forwarder Information

    Alert Syslog Forwarder Information enables the forwarding of Trellix IPS alerts to a Syslog Server. The Syslog forwarding enables you to view the forwarded alerts from a third-party Syslog application. The field details are described in the following table:

    Field Name

    Description

    Child Domain Notification Enabled

    Child notification has been enabled.

    Notification Profile Name

    Name of the notification profile.

    Syslog Server (Host Name Or IP Address)/Port

    Syslog server or port on which it is enabled.

    Protocol

    Syslog server using UDP or TCP connection

    Use SSL

    Use SSL when syslog server uses TCP

    Quarantine Enabled

    Quarantine enabled or disabled.

    Firewall Notification Information

    It is an optional Firewall feature that will log packets that are dropped or permitted based on your Access Rules. You can configure the Sensor to forward Firewall logs to Manager, where they are formatted and converted to Syslog messages and sent to the configured Syslog server. You can also configure the Sensor to directly send logs to the configured Syslog server. The field details are described in the following table:

    Field Name

    Description

    Syslog Forwarder Enabled

    Syslog forwarder has been enabled or disabled.

    Child Domain Notification Enabled

    Child notification has been enabled.

    Syslog Server (Host Name Or IP Address)

    Syslog server is enabled.

    Port

    Port on which it is forwarded.

    Quarantine

    To protect your network from security threats, Trellix IPS provides the Quarantine feature which quarantine and remediate the non-compliant network devices (or hosts) connecting to your network.

    Rule Objects

    Rule objects provide a convenient way of grouping together IP addresses, VLAN, CIDR or MAC addresses. The field details are described in the following table:

    Field Name

    Description

    Name

    Name of the rule object.

    Type

    This indicates the four different types of network address types that can be listed together in a network object.

    • IP Address

    • Network Address ( CIDR )

    • MAC Address

    • VLAN

    Value

    Enter the Value for the Type selected.

    Quarantine Zones

    Quarantine Zones are a set of ACL rules that define the zone of network access provided to a host subjected to Quarantine.

    The field details are described in the following table:

    Field Name

    Description

    Name

    The name of the Quarantine Zone.

    Description

    The description of the Quarantine Zone.

    Syslog Forwarding

    The Alert Notification Syslog action enables the forwarding of Trellix IPS alerts to a Syslog Server. Syslog forwarding enables you to view the forwarded alerts from a third-party Syslog application. For Syslog forwarding, the root domain and parent domains have the option to include alerts from all applicable child domains.

    Field Name

    Description

    Syslog

    Syslog forwarder has been enabled or disabled.

    Name

    Host Name of the Syslog Server where alerts will be sent.

    Facility

    Standard Syslog prioritization value. The choices are as follow:

    • Security/authorization (code 4)

    • Security/authorization (code 10)

    • Log audit (note 1)

    • Log alert (note 1)

    • Clock daemon (note 2)

    • Local user 0 (local0)

    • Local user 1 (local1)

    • Local user 2 (local2)

    • Local user 3 (local3)

    • Local user 4 (local4)

    • Local user 5 (local5)

    • Local user 6 (local6)

    • Local user 7 (local7)

    Priority

    The severity level of a higher or lesser priority.

    Remediation Portal

    To make the quarantined host clean of malicious traffic and thus compliant to the security policies of the network, Trellix IPS provides remediation by re-directing the HTTP traffic from the host to a Remediation Portal.

    Field Name

    Description

    Remediation Portal State

    Enable the redirection of HTTP traffic to the Remediation Portal.

    Remediation Portal IP Address

    Configure the Remediation Portal, by specifying the Remediation Portal IP Address.

    Remediation Portal URL

    Configure the Remediation Portal, by specifying the Remediation Portal URL

    IPS Settings

    The IPS Settings node in each admin domain facilitates actions related to configuration and management of IPS related policies configuration on the Trellix IPS.

    Quarantine

    Field Name

    Description

    State

    Whether Quarantine is enabled or not.

    Quarantine Zone

    The quarantine zone selected.

    Release Logic

    Whether the Sensor is configured to release the endpoint from quarantine automatically after a set timing or whether you have to manually release the endpoint from quarantine.

    Release After

    If the Sensor is configured to release the endpoint, what is the time duration after which the endpoint is released.

    Browser Message

    How is the browser message enabled.

    Quarantine Exceptions

    You can exclude certain hosts or network from being quarantined. This can be configured from the Quarantine Exceptions page of the Quarantine Configuration Wizard.

    Field Name

    Description

    Type

    The IP address, IPv4 Network, or Rule Object.

    Value

    Enter the Value for the Type selected.

    Description

    The description of the hosts or network.

    File Reputation

    The File Reputation Report provides you details of Trellix ePO&trade; (GTI) IP Reputation-related alerts such as Dirtiness Level, Matched fingerprint, Sensor Source IP, Source Port, etc.

    Fingerprints - GTI

    Field Name

    Description

    Maximum file size scanned

    4194304 bytes (for signature set 10.8 and higher) - fixed size up to which malware files are detected.

    Primary DNS Server

    The main DNS server - configured first.

    Secondary DNS Server

    The backup DNS server – configured next and if main DNS server fails to respond.

    Response Action

    Detect/Allow (Alert only), block, block and send TCP resets.

    Sensitivity

    The severity of malware to block can be controlled.

    Fingerprints - Custom

    Field Name

    Description

    Number of custom fingerprints

    The number of custom finger prints that are added.

    Maximum file size scanned

    4194304 bytes (for signature set 10.8 and higher)- fixed size up to which malware files are detected.

    Response Action

    Detect/Allow (Alert only), block, block and send TCP resets.

    File types supported

    Field Name

    Description

    GTI

    The Portable Executable (PE) files.

    Custom

    File types based on custom signatures.

    IVX Integration - Integration with IVX Appliance

    Field Name

    Description

    Enable IVX Integration

    IVX appliance Integration has been enabled or disabled.

    Enabled Integration with

    Integration has been enabled with IVX.

    IP Address

    IP address of the IVX broker(s) integrated with Trellix IPS.

    Manager to IVX Communication Port (TCP)

    Manager-to-IVX Appliance Communication Port number.

    IVX Integration - Integration with IVX Cloud

    Field Name

    Description

    Enable IVX Cloud Integration

    IVX Cloud Integration has been enabled or disabled.

    Enabled Integration with

    Integration has been enabled with IVX Cloud.

    Host Name

    Host name for the IVX Cloud service. The default host name is feapi.marketplace.apps.fireeye.com.

    Manager to IVX Cloud Communication Port

    Manager-to-IVX Cloud Communication Port number.

    Trellix Intelligent Sandbox Integration

    Field Name

    Description

    Enable Trellix Intelligent Sandbox Integration

    Trellix Intelligent Sandbox Integration has been enabled or disabled.

    Trellix Intelligent Sandbox IP Address

    IP address of Trellix Intelligent Sandbox integrated with Trellix IPS.

    Sensor-to-Intelligent Sandbox Communication Port (TCP)

    Sensor-to-Intelligent Sandbox Communication Port number.

    Manager-to-Intelligent Sandbox Communication Port (TCP)

    Manager-to-Intelligent Sandbox Communication Port number.