The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages expected in early November 2026. We hope you enjoy the updated experience.

Generate User Activity reports

Prev Next

The Audit report enables you to view the actions performed by Trellix IPS users. Similar to the generating a user activities audit option, this report allows you to view the actions of all users or a single user in one or more admin domains.

Note

You can create report templates and also schedule report generation on a daily or weekly basis for the Audit report.

To generate an audit report, do the following:

Task

  1. On the Manager Home page, click the Manager tab.
  2. Select <Admin Domain Name> → Reporting → Configuration Reports → User Activity.
  3. Select a filter from the Admin Domain drop-down list.

    Note

    The admin domain selected in the left pane has no impact on the reports generated. The Admin Domain drop-down list is explicitly to filter the reports that are generated.

  4. Select whether or not to include audit data from all child domains of the selected domain. (Include All Child Admin Domain Audit Data)
  5. Select "All Users" or a single user to audit. (Select User(s) to Audit)
  6. Select one or more Audit Categories. By default, all categories except Unspecified are selected. Audit categories are areas/resources where users can perform actions. Choose from the following (examples of each provided):
    • Unspecified — All actions not covered by the other categories
    • Admin Domain — Created an admin domain, generated a system log
    • User — Logged into the system, created a user, assigned a role to a user
    • Manager — Configured proxy server settings
    • Sensor — Configured ports, pushed configuration changes
    • IPS Policy — Created a policy, cloned a attack set profile
    • Report — Designed a scheduled report template, generated a report
    • Update Server — Configured Update Server settings, downloaded software
    • Operational Status — Delete Manager or Sensor related faults.
    • Alert — Acknowledge alerts, delete alerts.
    • NTBA — Reports all the network threat behavior analysis
    • FIPS Self Test — Reports all the audits related to FIPS mode crypto activity
    • ePolicy Orchestrator — Audit events related to ePO
    • Controller — Checks the Controller-Manager registration status
  7. Select Show Details to include detailed audit information in the report output, such as Date and Time when a change was made, username against each change, etc.
  8. Type the number of audit messages to show. The default is 10 messages. (Show x messages)
  9. Select from one of the following time options:
    • Up to Current Time — Displays the requested number of most recent messages
    • Ending (All messages before this date will be displayed) — Displays the requested number of messages starting from this time and proceeding backwards
    • Select Messages Between These Dates — Select the desired range of dates for activity by a user.
  10. Select the Output Format.
  11. Click Run Report to start the audit.
    • The fields displayed in the audit result are as follows:
      • Date — When an action was performed
      • Admin Domain — The domain in which the action was performed
      • User — Who performed the action
      • Attack Category — Audit category. That is, area/resource, where action was performed.
      • Action — Short description of the performed action
      • Result — Status of the performed action as either "Success" or "Failure"
      • Description — Verbose description of the performed action
    • The following additional fields are displayed if Show Details is selected:
      • Commit Comments — Comments that the user entered before committing the policy changes
      • Audit Data Details — Details of the changes made