The Reconnaissance report provides a summary of all reconnaissance (scans, sweeps, probes) attacks detected during a specified time frame.
Tip
This report is best used for analyzing only reconnaissance attacks detected by your device.
Task
-
Select Analysis → Event Reporting → Traditional Reports.
The IPS Events page is displayed.
- Click the Reconnaissance Attacks link.
-
Fill in the following fields to narrow your report:
- Admin Domain — Select the admin domain in which to view alerts.
Note
The admin domain selected in the left pane has no impact on the reports generated. The Admin Domain drop-down list is explicitly to filter the reports that are generated.
- Sensor:
- All Devices is checked by default. This displays information of all devices present at the selected Admin domain. To select your preference of devices, de-select the All Devices and select the devices from the list box.
- Include Child Admin Domains — Displays device information for child domains.
- Attack Severity — Select one or more from the Informational, Low, Medium, or High severities, which relate to attack impact.
- Alert State — Select one of the following to narrow the alerts:
- View unacknowledged alerts — All unacknowledged alerts in the system for the specified time frame. If you have acknowledged alerts during your selected time range, this option suppresses those alerts.
- View all alerts — (Default) both acknowledged and unacknowledged alerts for the specified time frame.
- Choose one of the following time spans:
- Select Attacks for this Day — Format is yyyy/mm/dd. Default is Manager server system date.
- Select Attacks Between these Dates — Format is yyyy/mm/dd hh:mm:ss. Default Begin Date is "oldest alert detected time" and default End Date is Manager server system time.
- Select Attacks in the past — Selects alerts from a point in the past relative to the current time. This time in the past can be months, weeks, days (Default), or hours. Type a time (yyyy/mm/dd hh:mm:ss) when the span of reporting time ends (default is Manager server system time).
- Admin Domain — Select the admin domain in which to view alerts.
- Select the Report Format.
- Click Run Report.