The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Generate User Defined reports

Prev Next

The User Defined report presents alerts based on user-customized parameters. This report provides the most flexibility by enabling you to selectively minimize the report output through alert data filtering. For example, you can view alerts for all deployed devices, for one device, for a single interface, or even just a sub-interface of a device. In the same manner, you can filter based on a specific source IP, destination IP, and so forth. The depth of each category enhances the quality of your forensic analysis.

Tip

This report is best used for generating a custom report based solely on the parameters you require for alert analysis.

Steps:

  1. Select Analysis → Event Reporting → Traditional Reports.

    The IPS Events page is displayed.

  2. Click the User Defined link.

  3. Fill out the form. The following fields are noteworthy:

    • Admin Domain — Select the admin domain in which to view alerts.

      Note

      The admin domain selected in the left pane has no impact on the reports generated. The Admin Domain drop-down list is explicitly to filter the reports that are generated.

    • Sensor:

      • All Devices is checked by default. This displays information of all devices present at the selected Admin domain. To select your preference of devices, de-select All Devices and select the devices from the list box.

      • Include Child Admin Domains — Displays device information for child domains, but information about interfaces belonging to devices in child domain are not displayed.

    • Interface — Default is All interfaces. To narrow the result, clear the All interfaces check box, then select the desired interface(s). The All interfaces check box is enabled only if you have selected a specific device in the Sensor field.

    • Detection Mechanism — Default is All detection mechanisms. To narrow the result, clear the All detection mechanisms check box, then select the desired mechanism(s).

    • Protocol — The default is Application Protocol. Based on the selection, the fields change to display relevant protocols. Select Reference Protocol to view alerts based on the attack definition instead of the alert's application protocol. You may want to select Reference Protocol, if you want to search for a protocol that tunnels through another protocol and is, therefore, hidden. For example, P2P traffic is often tunneled through HTTP traffic.

    • Application Protocol — Default is All protocols. To narrow the result, clear the All protocols checkbox, then select the desired protocol(s).

    • References Protocol — Default is All protocols. To narrow the result, clear the All protocols checkbox, then select the desired protocol(s).

    • Attack Category — Default is All Categories. To narrow the result, toggle the drop down menu and select the category you require. The Sub Category field is a subset of the Category field.

    • Attack Sub-Category — Default is All Sub Categories. To narrow the result, clear the All Sub Categories check box, then select the desired sub category or sub categories.

    • Source IP Address — Default is Any source IP address. To enter a specific source IP address, clear the Any source IP address check box, then type your entry. You can enter a netmask (*) for Class B, C, and D addresses. You can select either IPv4 or IPv6 type of IP addressing.

    • Source Port Number — Default is Any source port number. To enter a specific port, clear the Any source port number check box and type your entry.

    • Destination IP — Default is Any destination IP address. To type a specific destination IP address, clear the Any destination IP address check box, then type your entry. You can enter a netmask (*) for Class B, C, and D addresses. You can select either IPv4 or IPv6 type of IP addressing.

      Note

      IP addresses can be expressed with netmasks as follows: XXX.*.*.*, XXX.XXX.*.*, and XXX.XXX.XXX.*.

    • Destination Port Number — Default is Any destination port number. To enter a specific port, clear the Any destination port number check box and type your entry.

    • Direction of Attack (for Signature Attacks only) — Default is All (both Inbound and Outbound). Selecting both options will include those attacks with "unknown" (common for SPAN or Hub mode) directions.

    • Attack Severity — Select one or more from the Informational, Low, Medium, or High severities, which relate to attack impact.

    • Relevance — Select one or more from Relevant, Unknown, or Not Applicable levels, which is related to vulnerability relevancy.

    • Select Alert/Attack Type — To view all alerts, blocked alerts, or alerts/attack type for which the source endpoints were quarantined and remediated.

      To select the alert/attack type based on Quarantine feature, select the check box Quarantine. Next, select either of the check boxes- Quarantined or Quarantined & Remediated.

    • Alert State — Select one of the following to narrow the alerts:

      • View unacknowledged alerts — All unacknowledged alerts in the system for the specified time frame. If you have acknowledged alerts during your selected time range, this option suppresses those alerts.

      • View all alerts — (Default) both acknowledged and unacknowledged alerts for the specified time frame.

    • Attacks — Choose one of the following attacks:

      • Select Attacks for this Day — Format is yyyy/mm/dd. Default is Manager server system date.

      • Select Attacks Between These Dates — Format is yyyy/mm/dd hh:mm:ss. Default Begin Date is "oldest alert detected time" and default End Date is Manager server system time.

      • Select Attacks in the past — Selects alerts from a point in the past relative to the current time. This time in the past can be months, weeks, days (Default), or hours. Type a time (yyyy/mm/dd hh:mm:ss) when the span of reporting time ends (default is Manager server system time).

    • Fields of Interest — Checked fields appear as table columns in report output. All options are selected by default.

    • Organized by — Specify how you want the information to be organized in the report. Choices are Attack, Source IP, Destination IP, or Create Time. For example, if you choose Attack, then the information is organized by attack name in the reverse alphabetical order. Create Time is the alert generation time.

    • Select the Report Format.

  4. Click Run Report to generate a report.