The Trend Analysis report provides a high-level overview of trends and patterns in the collected alert data for a specified period of time or interval. A trend can be the number of alerts per hour for a day generated by all devices, the number of high severity exploit alerts per day for a week generated by a single interface on a device, and so on.
Note
You can generate a trend analysis report on all devices, a single device, a single interface on a device, or a single sub-interface.
Analyzing trends may provide an insight as to the type of alert activity being generated at different times of the day, week, or month. This data can help you devise a better security environment, or it may simply be used for presentation display when meeting to discuss your network security.
Note
Only users with root admin domain privileges can use the Trend Analysis Report.
The following categories and subcategories are available for trend analysis. During configuration, you must pick at least one category with a corresponding subcategory for your report. Each of the subcategories represents a specific trend during the interval you specify. If in one report you select multiple trend items for your report, each trend item has a separate graph and/or table for viewing the trend data. The categories and subcategories are as follows:
Severity— Number of attacks by severity
All [severities]
High [severity alerts]
Medium [severity alerts]
Low [severity alerts]
Informational [alerts]
Attack Category— Number of attacks by type
Policy Violation
Reconnaissance Attacks
Volume DoS
Exploit
Malware Attacks
Unique— Number of attacks by specific parameter
Attacks— Unique attacks
Destination IP— Unique destination addresses
Source IP— Unique source addresses
Tip
This report is best used for displaying general alert information for the most common parameters in a presentation-like format.
Steps:
Select Analysis → Event Reporting → Traditional Reports.
The IPS Events page is displayed.
Click the Trend Analysis link.
Select a Resource. A resource could be a device, interface on a device, or sub-interface. By default, only entire devices are available.
Note
Resource selection may include devices that have since been removed from your Manager. This is to provide you with the alert data generated by the now-deleted device during a period in the past.
Select one or more Trend Item(s), then click Add to List. The trend data for the selected trend items can be viewed in the generated Trend Analysis Report. If you want to remove a Trend Item from the list, select the Trend Item, then click Remove Selection.
Select a Trend Reporting Interval from one of the following:
Hour— Display each Trend Item's alert count per hour
Day— Display each Trend Item's alert count per day
Select a Trend Reporting Period for Attacks. Choose one of the following time spans:
Select Attacks for this Day— Format is yyyy/mm/dd. Default is Manager server system date. It detects all the attacks for that particular date.
Select Attacks Between these Dates— Format is yyyy/mm/dd hh:mm:ss. Default Begin Date is "oldest alert detected time" and default End Date is Manager server system time. It detects all the attacks between the dates selected.
Select Attacks in the past— Selects alerts from a point in the past relative to the current time. This time in the past can be months, weeks, days (Default), or hours. Type a time (yyyy/mm/dd hh:mm:ss) when the span of reporting time ends (default is Manager server system time). It detects all the attacks for the number of days, weeks, or months selected.
Note
The Trend Reporting Period end date cannot be in the future.
Select the Report Format.
Select the Report Content delivery method. Choices are: Bar Chart, Table Only, or Table and Chart.
Click Run Report. The Trend Analysis Report is generated according to the configuration values set.
Note
The Configure button has multiple options.