The User Activity report enables you to view the actions performed by Trellix IPS users. Similar to the generating a user activities audit option, this report allows you to view the actions of all users or a single user in one or more admin domains.
Note
You can create report templates and also schedule report generation on a daily or weekly basis for this report.
To generate the User Activity report, do the following:
Steps:
On the Manager Home page, click the Manager tab.
Select <Admin Domain Name> → Reporting → Configuration Reports → User Activity.
Select the required domain from the Admin Domain drop-down list.
Note
The admin domain selected in the left pane has no impact on the reports generated. The Admin Domain drop-down list is explicitly to filter the reports that are generated.
Select the Include All Child Admin Domain Audit Data option if you want to include audit data from all the child domains of the selected domain.
Select the required user from the Select User(s) to Audit drop-down list.
Select one or more Audit Categories using the drop-down list. By default, all categories except Unspecified are selected. Audit categories are areas/resources where users can perform actions. Choose from the following (examples of each provided):
Unspecified — All actions not covered by the other categories
Admin Domain — Created an admin domain, generated a system log
User — Logged into the system, created a user, assigned a role to a user
Manager — Configured proxy server settings
Sensor — Configured ports, pushed configuration changes
IPS Policy — Created a policy, cloned a attack set profile
Report — Designed a scheduled report template, generated a report
Update Server — Configured Update Server settings, downloaded software
Operational Status — Delete Manager or Sensor related faults.
Alert — Acknowledge alerts, delete alerts.
FIPS Self Test — Reports all the audits related to FIPS mode crypto activity
ePolicy Orchestrator — Audit events related to ePO
Controller — Checks the Controller-Manager registration status
Select Show Details to include detailed audit information in the report output, such as Date and Time when a change was made, username against each change, etc.
Type the number of audit messages to show using the Show field. The default is 10 messages.
Select the Duration — Select from one of the following duration from the drop-down list:
Last 5 minutes
Last 1 hour
Last 6 hours
Last 12 hours
Last 24 hours
Last 48 hours
Last 7 days
Last 14 days
Custom time period —Enables you to select and view specific audit messages between a Start Time and End Time (you can specify both the date and time and click Apply)
Select the Report Format.
Click Run to generate the report.
The fields displayed in the audit result are as follows:
Date — When an action was performed
Admin Domain — The domain in which the action was performed
User — Who performed the action
Attack Category — Audit category. That is, area/resource, where action was performed.
Action — Short description of the performed action
Result — Status of the performed action as either "Success" or "Failure"
Description — Verbose description of the performed action
The following additional fields are displayed if Show Details is selected:
Commit Comments — Comments that the user entered before committing the policy changes
Audit Data Details — Details of the changes made