Report overview
Report prerequisites
Generating an IPS top N attacks report (Web UI)
Scheduling an IPS top N attacks report (Web UI)
Report Overview
The Top N Attacks report lists the specified number (1 through 100) of most-triggered IPS rules during the specified reporting period:
Rule Description—Name of the IPS rule that detected an event.
Attack Count—Number of events detected by the rule.
You can request the report to be output as a PDF file or as a CSV file in the /data/reports folder on the local drive. The format of the report file name is ips_top_n_attack_hostName_dateCreated_timeCreated, where hostName is the host name assigned to your appliance, and dateCreated and timeCreated identify the date and time the report was created.
Note
If you need a report that lists IPS rules that triggered MVX-correlated IPS events, you can generate an IPS Top N MVX-Correlated report. Specify any value for N, from 1 through 100, and then view the report section titled Top <n> Attacks. See IPS top N MVX-correlated.
Report prerequisites
Log in to the Web UI of the IPS appliance as Monitor, Analyst, Operator, or Admin.
Generating an IPS top N attacks report (Web UI)
To generate a report of the IPS top N attacks:
In the Web UI, choose Reports > Reports.
In the Report Type field, select Top N Attacks.
In the Report Format field, select the report output format.
pdf—Write the report to an Adobe PDF file.
csv—Write the report to a CSV file.
In the Top field, select the number of attacks to be reported. Valid range is 1 ‑ 100.
In the Interface field, select the monitoring interfaces to be reported.
In the Time frame field, select the period of time that the report is to cover.
past day—The past 24 hours.
past week—The past 7 days.
past month—The past 1 month.
between—Between the From and To dates and times you specify.
Click Generate Report. The page confirms receipt of your request.
When the report is complete, a link to the report file appears below the Generate Reports label.
Scheduling an IPS top N attacks report (Web UI)
To schedule a report of the IPS top N attacks:
In the Web UI, choose Reports > Schedule.
In the Scheduled field, select the report frequency:
hourly
daily
weekly
monthly
In the Time fields, specify the report time.
If you selected a weekly report, specify the report day of the week in the WeekDay field.
If you selected a monthly report, specify the report day of the month in the MonthDay field.
In the Delivery field, select the report delivery method:
email—Deliver the report as a file attached to email. For information about configuring email notification, see the Network Security User Guide.
>file—Deliver the report as a file linked from the Web UI.
In the Report Type field, select Top N Attacks.
In the Report Format field, select the report output format.
pdf—Write the report to an Adobe PDF file
csv—Write the report to a CSV file.
In the Top field, select the number of attacks to be reported. Valid range is 1 ‑ 100.
In the Interface field, select the monitoring interfaces to be reported.
In the Time frame field, select the period of time that the report is to cover.
past day—The past 24 hours.
past week—The past 7 days.
past month—The past 1 month.
between—Between the From and To dates and times you specify.
Click Schedule Report. The page confirms receipt of your request.
When the report is complete, a link to the report file appears below the Generate Reports label.