This topic covers the following information:
Report overview
Report prerequisites
Generating an IPS top N attackers report (Web UI)
Scheduling an IPS top N attackers report (Web UI)
Report overview
The Top N Attackers report lists the specified number (1 through 100) of most-active attackers found by IPS rules during the specified reporting period:
Attacker—IP address of an attacker host found by IPS rules.
# of Victims—Number of victim hosts associated with the attacker host.
You can request the report to be output as a PDF file or as a CSV file in the /data/reports folder on the local drive. The format of the report file name is ips_top_n_attacker_hostName_dateCreated_timeCreated, where hostName is the host name assigned to your appliance, and dateCreated and timeCreated identify the date and time the report was created.
Note
If you need a report that lists attacker hosts that sent MVX-correlated attacks detected by IPS rules, you can generate an IPS Top N MVX-Correlated report. Specify any value for N, from 1 through 100, and then view the report section titled Top <n> Attackers. See IPS top N MVX-correlated.
Report prerequisites
Log in to the Web UI of the IPS appliance as Monitor, Analyst, Operator, or Admin.
Generating an IPS top N attackers report (Web UI)
To generate a report of the IPS Top N Attackers:
In the Web UI, choose Reports > Reports.
In the Report Type field, select Top N Attackers.
In the Report Format field, select the report output format.
pdf—Write the report to an Adobe PDF file.
csv—Write the report to a CSV file.
In the Top field, select the number of attacks to be reported. Valid range is 1 ‑ 100.
In the Interface field, select the monitoring interfaces to be reported.
In the Time frame field, select the period of time that the report is to cover.
past day—The past 24 hours.
past week—The past 7 days.
past month—The past 1 month.
between—Between the From and To dates and times you specify.
Click Generate Report. The page confirms receipt of your request.
When the report is complete, a link to the report file appears below the Generate Reports label.
Scheduling an IPS top N attackers Report (Web UI)
To schedule a report of the IPS top N attackers:
In the Web UI, choose Reports > Schedule.
In the Scheduled field, select the report frequency:
hourly
daily
weekly
monthly
In the Time fields, specify the report time.
If you selected a weekly report, specify the report day of the week in the WeekDay field.
If you selected a monthly report, specify the report day of the month in the MonthDay field.
In the Delivery field, select the report delivery method:
email—Deliver the report as a file attached to email. For information about configuring email notification, see the Network Security User Guide.
file—Deliver the report as a file linked from the Web UI.
In the Report Type field, select Top N Attackers.
In the Report Format field, select the report output format.
pdf—Write the report to an Adobe PDF file.
csv—Write the report to a CSV file.
In the Top field, select the number of attacks to be reported. Valid range is 1 ‑ 100.
In the Interface field, select the monitoring interfaces to be reported.
In the Time frame field, select the period of time that the report is to cover.
past day—The past 24 hours.
past week—The past 7 days.
past month—The past 1 month.
between—Between the From and To dates and times you specify.
Click Schedule Report. The page confirms receipt of your request.
When the report is complete, a link to the report file appears below the Generate Reports label.