The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Generate Reconnaissance Attacks reports

Prev Next

The Reconnaissance report provides a summary of all reconnaissance (scans, sweeps, probes) attacks detected during a specified time frame.

Tip

This report is best used for analyzing only reconnaissance attacks detected by your device.

Steps:

  1. Select Analysis → Event Reporting → Traditional Reports.

    The IPS Events page is displayed.

  2. Click the Reconnaissance Attacks link.

  3. Fill in the following fields to narrow your report:

    • Admin Domain — Select the admin domain in which to view alerts.

      Note

      The admin domain selected in the left pane has no impact on the reports generated. The Admin Domain drop-down list is explicitly to filter the reports that are generated.

    • Sensor:

      • All Devices is checked by default. This displays information of all devices present at the selected Admin domain. To select your preference of devices, de-select the All Devices and select the devices from the list box.

      • Include Child Admin Domains — Displays device information for child domains.

    • Attack Severity — Select one or more from the Informational, Low, Medium, or High severities, which relate to attack impact.

    • Alert State — Select one of the following to narrow the alerts:

      • View unacknowledged alerts — All unacknowledged alerts in the system for the specified time frame. If you have acknowledged alerts during your selected time range, this option suppresses those alerts.

      • View all alerts — (Default) both acknowledged and unacknowledged alerts for the specified time frame.

    • Choose one of the following time spans:

      • Select Attacks for this Day — Format is yyyy/mm/dd. Default is Manager server system date.

      • Select Attacks Between these Dates — Format is yyyy/mm/dd hh:mm:ss. Default Begin Date is "oldest alert detected time" and default End Date is Manager server system time.

      • Select Attacks in the past — Selects alerts from a point in the past relative to the current time. This time in the past can be months, weeks, days (Default), or hours. Type a time (yyyy/mm/dd hh:mm:ss) when the span of reporting time ends (default is Manager server system time).

  4. Select the Report Format.

  5. Click Run Report.