The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Generate Trend Analysis reports

Prev Next

The Trend Analysis report provides a high-level overview of trends and patterns in the collected alert data for a specified period of time or interval. A trend can be the number of alerts per hour for a day generated by all devices, the number of high severity exploit alerts per day for a week generated by a single interface on a device, and so on.

Note

You can generate a trend analysis report on all devices, a single device, a single interface on a device, or a single sub-interface.

Analyzing trends may provide an insight as to the type of alert activity being generated at different times of the day, week, or month. This data can help you devise a better security environment, or it may simply be used for presentation display when meeting to discuss your network security.

Note

Only users with root admin domain privileges can use the Trend Analysis Report.

The following categories and subcategories are available for trend analysis. During configuration, you must pick at least one category with a corresponding subcategory for your report. Each of the subcategories represents a specific trend during the interval you specify. If in one report you select multiple trend items for your report, each trend item has a separate graph and/or table for viewing the trend data. The categories and subcategories are as follows:

  • Severity— Number of attacks by severity

    • All [severities]

    • High [severity alerts]

    • Medium [severity alerts]

    • Low [severity alerts]

    • Informational [alerts]

  • Attack Category— Number of attacks by type

    • Policy Violation

    • Reconnaissance Attacks

    • Volume DoS

    • Exploit

    • Malware Attacks

  • Unique— Number of attacks by specific parameter

    • Attacks— Unique attacks

    • Destination IP— Unique destination addresses

    • Source IP— Unique source addresses

      Tip

      This report is best used for displaying general alert information for the most common parameters in a presentation-like format.

Steps:

  1. Select Analysis → Event Reporting → Traditional Reports.

    The IPS Events page is displayed.

  2. Click the Trend Analysis link.

  3. Select a Resource. A resource could be a device, interface on a device, or sub-interface. By default, only entire devices are available.

    Note

    Resource selection may include devices that have since been removed from your Manager. This is to provide you with the alert data generated by the now-deleted device during a period in the past.

  4. Select one or more Trend Item(s), then click Add to List. The trend data for the selected trend items can be viewed in the generated Trend Analysis Report. If you want to remove a Trend Item from the list, select the Trend Item, then click Remove Selection.

  5. Select a Trend Reporting Interval from one of the following:

    • Hour— Display each Trend Item's alert count per hour

    • Day— Display each Trend Item's alert count per day

  6. Select a Trend Reporting Period for Attacks. Choose one of the following time spans:

    • Select Attacks for this Day— Format is yyyy/mm/dd. Default is Manager server system date. It detects all the attacks for that particular date.

    • Select Attacks Between these Dates— Format is yyyy/mm/dd hh:mm:ss. Default Begin Date is "oldest alert detected time" and default End Date is Manager server system time. It detects all the attacks between the dates selected.

    • Select Attacks in the past— Selects alerts from a point in the past relative to the current time. This time in the past can be months, weeks, days (Default), or hours. Type a time (yyyy/mm/dd hh:mm:ss) when the span of reporting time ends (default is Manager server system time). It detects all the attacks for the number of days, weeks, or months selected.

    Note

    The Trend Reporting Period end date cannot be in the future.

  7. Select the Report Format.

  8. Select the Report Content delivery method. Choices are: Bar Chart, Table Only, or Table and Chart.

  9. Click Run Report. The Trend Analysis Report is generated according to the configuration values set.

    Note

    The Configure button has multiple options.