This topic covers the following information:
Report overview
Report prerequisites
Generating an IPS executive summary report (Web UI)
Scheduling an IPS executive summary report (Web UI)
Report overview
The IPS Executive Summary report provides a high-level view of IPS statistics for the specified reporting period.
You can request the report to be output as a PDF file or as a CSV file in the /data/reports folder on the local drive. The format of the report file name is ips_executive_summary_hostName_dateCreated_timeCreated, where hostName is the host name assigned to your appliance, and dateCreated and timeCreated identify the date and time the report was created.
The report consists of several sections: a summary of IPS events, IPS Top 10 lists, a percentage breakdown of IPS critical and major events (severity levels 4 ‑ 10) by threat category, and a trend chart of IPS critical and major alerts.
Events summary
This section of the report summarizes IPS event counts for the specified reporting period:
MVX correlated IPS—Total number of IPS alerts. The platform generates an IPS alert for a traffic flow that matches one or more IPS rules and has also been correlated with one or more zero-day attacks confirmed separately by the MVX engine. Another section of the report provides more detail. See Top 10 MVX‑correlated IPS events.
IPS Critical—Number of IPS events of threat severity level 7 ‑ 10, as shown in the Hosts tab, Alerts tab, and the IPS Events page by an icon such as the following:

IPS Major—Number of IPS events of threat severity level 4 ‑ 6, as shown in the Hosts tab, Alerts tab, and the IPS Events page by an icon such as the following:

IPS Minor—Number of IPS events of threat severity level 1 ‑ 3, as shown in the Hosts tab, Alerts tab, and the IPS Events page by an icon such as the following:

# of Attackers—Number of unique attackers associated with IPS events.
# of Victim Hosts—Number of unique victims associated with IPS events.
Top 10 attacks by rules
This section of the report lists the ten most-triggered IPS rules for the specified reporting period.
Rule Description—Name of the IPS rule that detected an event.
Attack Count—Number of events detected by the rule.
Note
If you need a report that lists a specific number of most-triggered IPS rules, you can generate an IPS Top N Attacks report. Specify any value for N, from 1 through 100. See IPS top N attacks.
Top 10 MVX‑correlated IPS events
This section of the report lists the ten most-triggered IPS rules that detected events that correlate with MVX-verified malware events during the specified reporting period.
IPS Rule Description—Name of an IPS rule that detected an MVX-correlated event.
# of MVX Correlated IPS Events—Number of MVX-correlated events detected by the rule.
Note
If you need a report that lists a specific number of most-triggered IPS rules that detected MVX-correlated events, you can generate an IPS Top N MVX-Correlated report. Specify any value for N, from 1 through 100. See IPS top N MVX-correlated.
Top 10 attackers
This section of the report lists the ten most-active attackers found by IPS rules during the specified reporting period.
Attacker—IP address of an attacker host found by IPS rules.
# of Victims—Number of victim hosts associated with the attacker host.
Note
If you need a report that lists a specific number of most-active attackers found by IPS rules, you can generate an IPS Top N Attackers report. Specify any value for N, from 1 through 100. See IPS top N attackers.
Top 10 victims
This section of the report lists the ten most-attacked victims found by IPS rules during the specified reporting period.
Victim—IP address of a victim host found by IPS rules.
# of Rules Matched—Number of IPS rules that matched attacks on the victim.
Note
If you need a report that lists a specific number of most-attacked victims found by IPS rules, you can generate an IPS Top N Victims report. Specify any value for N, from 1 through 100. See. IPS top N victims.
Top attacks by category
This section of the report shows the percentage breakdown of critical and major events (severity levels 4 ‑ 10) by category during the specified reporting period. The PDF formatted report displays a color-coded pie chart of the percentage breakdown for the attack categories. The CSV formatted report lists both the percentage and event count for each attack category
IPS alert trend analysis
This section of the report displays a chart that tracks the number of infections associated with critical IPS events (severity levels 7 ‑ 10) and major IPS events (severity levels 4 ‑6) detected during the specified reporting period.
Report prerequisites
Log in to the Web UI of the IPS appliance as Monitor, Analyst, Operator, or Admin.
Generating an IPS executive summary report (Web UI)
To generate an IPS executive summary report:
Choose Reports > Reports.
In the Report Type field, select IPS Executive Summary.
In the Report Format field, select the report output format.
pdf—Write the report to an Adobe PDF file.
csv—Write the report to a CSV file.
In the Time frame field, select the period of time that the report is to cover.
past day—Report covers analysis performed during the past 24 hours.
past week—Report covers analysis performed during the past 7 days.
past month—Report covers analysis performed during the past 1 month.
between—Report covers analysis performed between the specified From date and time and the specified To date and time.
Click Generate Report. The page confirms receipt of your request.
When the report is complete, a link to the report file appears below the Generate Reports label.
Scheduling an IPS executive summary report (Web UI)
To schedule an IPS executive summary report:
In the Web UI, choose Reports > Schedule.
In the Scheduled field, select the report frequency:
hourly
daily
weekly
monthly
In the Time fields, specify the report time
If you selected a weekly report, specify the report day of the week in the WeekDay field.
If you selected a monthly report, specify the report day of the month in the MonthDay field.
In the Delivery field, select the report delivery method:
email—Deliver the report as a file attached to email. For information about configuring email notification, see the Network Security User Guide.
file—Deliver the report as a file linked from the Web UI.
In the Report Type field, select IPS Executive Summary.
In the Report Format field, select the report output format.
pdf—Write the report to an Adobe PDF file.
csv—Write the report to a CSV file.
In the Time frame field, select the period of time that the report is to cover.
past day—Report covers analysis performed during the past 24 hours.
past week—Report covers analysis performed during the past 7 days.
past month—Report covers analysis performed during the past 1 month.
between—Report covers analysis performed between the specified From date and time and the specified To date and time.
Click Schedule Report. The scheduled report is added to the top of the scheduling list.