The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

IPS alerts

Prev Next

This topic covers the following information:

  • Report overview

  • Report prerequisites

  • Generating an IPS alerts report (Web UI)

  • Scheduling an IPS alerts report (Web UI)

Report overview

The IPS Alerts report provides all alert details by alert type over the timeframe selected.

The report is output to a CSV file in the /data/reports folder on the local drive. The format of the report file name is ips_events_hostName_dateCreated_timeCreated, where hostName is the host name assigned to your appliance, and dateCreated and timeCreated identify the date and time the report was created.

Each entry in the IPS Alerts report displays the following information about an attack detected by an IPS rule.

  • Time (UTC)—Date and time of the most recent occurrence of the event.

  • Victim IP—IP address of the victim host.

  • Attacker IP—IP address of the attacker host.

  • CVE-ID—If the IPS rule used to detect the event is associated with a security vulnerability description in the Common Vulnerabilities and Exposures (CVE) database, this field displays the CVE identification number. Otherwise, this field is empty.

  • Severity—Event severity estimates the likelihood that the targeted host was compromised by the event.

    • A value from 7 to 10 is a Critical severity level.

    • A value from 4 to 6 is a Major severity level.

    • A value from 1 to 3 is a Minor severity level.

  • # IPS Events—Number of IPS events of this type (same victim, same attacker, and same signature ID).

  • Rule—Name of the IPS rule used to detect the event.

  • Category—Attack category. For details, see the ips policy match command description in the CLI Command Reference.

  • Protocol—Presentation-layer protocol used as the attack vector.

Report prerequisites
  • Log in to the Web UI of the IPS appliance as Monitor, Analyst, Operator, or Admin.

Generating an IPS alerts report (Web UI)

To generate an IPS Alerts report:

  1. Choose Reports > Reports.

  2. In the Report Type field, select IPS Alerts.

  3. In the Time frame field, select the period of time that the report is to cover.

    • past day—Report covers analysis performed during the past 24 hours.

    • past week—Report covers analysis performed during the past 7 days.

    • past month—Report covers analysis performed during the past 1 month.

    • between—Report covers analysis performed between the specified From date and time and the specified To date and time.

  4. Click Generate Report.

    When the report is complete, a link to the report file appears below the Generate Reports label.

Scheduling an IPS Alerts Report (Web UI)

To schedule an IPS Alerts report:

  1. In the Web UI, choose Reports > Schedule.

  2. In the Scheduled field, select the report frequency:

    • hourly

    • daily

    • weekly

    • monthly

  3. In the Time fields, specify the report time.

  4. If you selected a weekly report, specify the report day of the week in the WeekDay field.

  5. If you selected a monthly report, specify the report day of the month in the MonthDay field.

  6. In the Delivery field, select the report delivery method:

    • email—Deliver the report as a file attached to email. For information about configuring email notification, see the Network Security User Guide.

    • file—Deliver the report as a file linked from the Web UI.

  7. In the Report Type field, select IPS Alerts.

  8. In the Time frame field, select the period of time that the report is to cover.

    • past day—Report covers analysis performed during the past 24 hours.

    • past week—Report covers analysis performed during the past 7 days.

    • past month—Report covers analysis performed during the past 1 month.

    • between—Report covers analysis performed between the specified From date and time and the specified To date and time.

  9. Click Schedule Report. The scheduled report is added to the top of the scheduling list.