The Audit report enables you to view the actions performed by Trellix IPS users. Similar to the generating a user activities audit option, this report allows you to view the actions of all users or a single user in one or more admin domains.
Note
You can create report templates and also schedule report generation on a daily or weekly basis for the Audit report.
To generate an audit report, do the following:
Task
- On the Manager Home page, click the Manager tab.
- Select <Admin Domain Name> → Reporting → Configuration Reports → User Activity.
-
Select a filter from the
Admin Domain drop-down list.
Note
The admin domain selected in the left pane has no impact on the reports generated. The Admin Domain drop-down list is explicitly to filter the reports that are generated.
- Select whether or not to include audit data from all child domains of the selected domain. (Include All Child Admin Domain Audit Data)
- Select "All Users" or a single user to audit. (Select User(s) to Audit)
-
Select one or more
Audit Categories. By default, all categories except Unspecified are selected. Audit categories are areas/resources where users can perform actions. Choose from the following (examples of each provided):
- Unspecified — All actions not covered by the other categories
- Admin Domain — Created an admin domain, generated a system log
- User — Logged into the system, created a user, assigned a role to a user
- Manager — Configured proxy server settings
- Sensor — Configured ports, pushed configuration changes
- IPS Policy — Created a policy, cloned a attack set profile
- Report — Designed a scheduled report template, generated a report
- Update Server — Configured Update Server settings, downloaded software
- Operational Status — Delete Manager or Sensor related faults.
- Alert — Acknowledge alerts, delete alerts.
- NTBA — Reports all the network threat behavior analysis
- FIPS Self Test — Reports all the audits related to FIPS mode crypto activity
- ePolicy Orchestrator — Audit events related to ePO
- Controller — Checks the Controller-Manager registration status
- Select Show Details to include detailed audit information in the report output, such as Date and Time when a change was made, username against each change, etc.
- Type the number of audit messages to show. The default is 10 messages. (Show x messages)
-
Select from one of the following time options:
- Up to Current Time — Displays the requested number of most recent messages
- Ending (All messages before this date will be displayed) — Displays the requested number of messages starting from this time and proceeding backwards
- Select Messages Between These Dates — Select the desired range of dates for activity by a user.
- Select the Output Format.
-
Click
Run Report to start the audit.
- The fields displayed in the audit result are as follows:
- Date — When an action was performed
- Admin Domain — The domain in which the action was performed
- User — Who performed the action
- Attack Category — Audit category. That is, area/resource, where action was performed.
- Action — Short description of the performed action
- Result — Status of the performed action as either "Success" or "Failure"
- Description — Verbose description of the performed action
- The following additional fields are displayed if
Show Details is selected:
- Commit Comments — Comments that the user entered before committing the policy changes
- Audit Data Details — Details of the changes made
- The fields displayed in the audit result are as follows: