The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Generate User Activity reports

Prev Next

The User Activity report enables you to view the actions performed by Trellix IPS users. Similar to the generating a user activities audit option, this report allows you to view the actions of all users or a single user in one or more admin domains.

Note

You can create report templates and also schedule report generation on a daily or weekly basis for this report.

To generate the User Activity report, do the following:

Steps:

  1. On the Manager Home page, click the Manager tab.

  2. Select <Admin Domain Name> → Reporting → Configuration Reports → User Activity.

  3. Select the required domain from the Admin Domain drop-down list.

    Note

    The admin domain selected in the left pane has no impact on the reports generated. The Admin Domain drop-down list is explicitly to filter the reports that are generated.

  4. Select the Include All Child Admin Domain Audit Data option if you want to include audit data from all the child domains of the selected domain.

  5. Select the required user from the Select User(s) to Audit drop-down list.

  6. Select one or more Audit Categories using the drop-down list. By default, all categories except Unspecified are selected. Audit categories are areas/resources where users can perform actions. Choose from the following (examples of each provided):

    • Unspecified — All actions not covered by the other categories

    • Admin Domain — Created an admin domain, generated a system log

    • User — Logged into the system, created a user, assigned a role to a user

    • Manager — Configured proxy server settings

    • Sensor — Configured ports, pushed configuration changes

    • IPS Policy — Created a policy, cloned a attack set profile

    • Report — Designed a scheduled report template, generated a report

    • Update Server — Configured Update Server settings, downloaded software

    • Operational Status — Delete Manager or Sensor related faults.

    • Alert — Acknowledge alerts, delete alerts.

    • FIPS Self Test — Reports all the audits related to FIPS mode crypto activity

    • ePolicy Orchestrator — Audit events related to ePO

    • Controller — Checks the Controller-Manager registration status

  7. Select Show Details to include detailed audit information in the report output, such as Date and Time when a change was made, username against each change, etc.

  8. Type the number of audit messages to show using the Show field. The default is 10 messages.

  9. Select the Duration — Select from one of the following duration from the drop-down list:

    • Last 5 minutes

    • Last 1 hour

    • Last 6 hours

    • Last 12 hours

    • Last 24 hours

    • Last 48 hours

    • Last 7 days

    • Last 14 days

    • Custom time period —Enables you to select and view specific audit messages between a Start Time and End Time (you can specify both the date and time and click Apply)

  10. Select the Report Format.

  11. Click Run to generate the report.

    The fields displayed in the audit result are as follows:

    • Date — When an action was performed

    • Admin Domain — The domain in which the action was performed

    • User — Who performed the action

    • Attack Category — Audit category. That is, area/resource, where action was performed.

    • Action — Short description of the performed action

    • Result — Status of the performed action as either "Success" or "Failure"

    • Description — Verbose description of the performed action

    The following additional fields are displayed if Show Details is selected:

    • Commit Comments — Comments that the user entered before committing the policy changes

    • Audit Data Details — Details of the changes made