The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

IPS top N attacks

Prev Next

  • Report overview

  • Report prerequisites

  • Generating an IPS top N attacks report (Web UI)

  • Scheduling an IPS top N attacks report (Web UI)

Report Overview

The Top N Attacks report lists the specified number (1 through 100) of most-triggered IPS rules during the specified reporting period:

  • Rule Description—Name of the IPS rule that detected an event.

  • Attack Count—Number of events detected by the rule.

You can request the report to be output as a PDF file or as a CSV file in the /data/reports folder on the local drive. The format of the report file name is ips_top_n_attack_hostName_dateCreated_timeCreated, where hostName is the host name assigned to your appliance, and dateCreated and timeCreated identify the date and time the report was created.

Note

If you need a report that lists IPS rules that triggered MVX-correlated IPS events, you can generate an IPS Top N MVX-Correlated report. Specify any value for N, from 1 through 100, and then view the report section titled Top <n> Attacks. See IPS top N MVX-correlated.

Report prerequisites
  • Log in to the Web UI of the IPS appliance as Monitor, Analyst, Operator, or Admin.

Generating an IPS top N attacks report (Web UI)

To generate a report of the IPS top N attacks:

  1. In the Web UI, choose Reports > Reports.

  2. In the Report Type field, select Top N Attacks.

  3. In the Report Format field, select the report output format.

    • pdf—Write the report to an Adobe PDF file.

    • csv—Write the report to a CSV file.

  4. In the Top field, select the number of attacks to be reported. Valid range is 1 ‑ 100.

  5. In the Interface field, select the monitoring interfaces to be reported.

  6. In the Time frame field, select the period of time that the report is to cover.

    • past day—The past 24 hours.

    • past week—The past 7 days.

    • past month—The past 1 month.

    • between—Between the From and To dates and times you specify.

  7. Click Generate Report. The page confirms receipt of your request.

    When the report is complete, a link to the report file appears below the Generate Reports label.

Scheduling an IPS top N attacks report (Web UI)

To schedule a report of the IPS top N attacks:

  1. In the Web UI, choose Reports > Schedule.

  2. In the Scheduled field, select the report frequency:

    • hourly

    • daily

    • weekly

    • monthly

  3. In the Time fields, specify the report time.

  4. If you selected a weekly report, specify the report day of the week in the WeekDay field.

  5. If you selected a monthly report, specify the report day of the month in the MonthDay field.

  6. In the Delivery field, select the report delivery method:

    • email—Deliver the report as a file attached to email. For information about configuring email notification, see the Network Security User Guide.

    • >file—Deliver the report as a file linked from the Web UI.

  7. In the Report Type field, select Top N Attacks.

  8. In the Report Format field, select the report output format.

    • pdf—Write the report to an Adobe PDF file

    • csv—Write the report to a CSV file.

  9. In the Top field, select the number of attacks to be reported. Valid range is 1 ‑ 100.

  10. In the Interface field, select the monitoring interfaces to be reported.

  11. In the Time frame field, select the period of time that the report is to cover.

    • past day—The past 24 hours.

    • past week—The past 7 days.

    • past month—The past 1 month.

    • between—Between the From and To dates and times you specify.

  12. Click Schedule Report. The page confirms receipt of your request.

    When the report is complete, a link to the report file appears below the Generate Reports label.