This topic covers the following information:
Report overview
Report prerequisites
Generating an IPS top N MVX-correlated report (Web UI)
Scheduling an IPS top N MVX-correlated report (Web UI)
Report overview
For each monitoring interface you specify, the IPS Top N MVX-Correlated report contains information about MVX-correlated attacks detected using IPS rules. The report provides the top MVX-correlated IPS events, the top perpetrators of MVX-correlated IPS events, and the top victims of MVX-correlated IPS events.
You can request the report to be output as a PDF file or as a CSV file in the /data/reports folder on the local drive. The format of the report file name is ips_top_n_mvx_correlated_hostName_dateCreated_timeCreated, where hostName is the host name assigned to your appliance, and dateCreated and timeCreated identify the date and time the report was created.
The report contains the following sections for each active monitoring interface:
Top N attacks
This section of the report identifies the top N IPS rules that detected attacks during the specified reporting period, including the number of associated attacks.
Report field name | Report field description |
|---|---|
# | List item number. |
Rule Description | Descriptive name of an IPS rule used to detect MVX-correlated attacks. |
# of Times Verified | Number of MVX-correlated attacks detected by the IPS rule during the specified reporting period. |
Top N attackers
This section of the report identifies the IP addresses of the top N attackers responsible for the most attacks during the specified reporting period.
Report field name | Report field description |
|---|---|
# | List item number. |
Attacker | IP address of attacker responsible for an MVX-correlated IPS event. |
# of Victims | Number of victims of the MVX-correlated attacks detected by IPS rules and sent by this attacker during the specified reporting period. |
Top N victims
This section of the report identifies the top N victims of the most attacks detected by IPS rules during the specified reporting period.
Report field name | Report field description |
|---|---|
# | List item number. |
Victim | IP address of a victim of an attack detected using an IPS rule. |
# of Rules Matched | Number of IPS rules used to detect attacks on the victim during the specified reporting period. |
Report prerequisites
Log in to the Web UI of the IPS appliance as Monitor, Analyst, Operator, or Admin.
Generating an IPS top N MVX-correlated report (Web UI)
To generate an IPS top N MVX-correlated report:
In the Web UI, choose Reports > Reports.
In the Report Type field, select IPS Top N MVX Correlated.
In the Report Format field, select the report output format.
pdf—Write the report to an Adobe PDF file.
csv—Write the report to a CSV file.
In the Top field, select the number of attacks to be reported. Valid range is 1 ‑ 100.
In the Interface field, select the monitoring interfaces to be reported.
In the Time frame field, select the period of time that the report is to cover.
past day—The past 24 hours.
past week—The past 7 days.
past month—The past 1 month.
between—Between the From and To dates and times you specify.
Click Generate Report. The page confirms receipt of your request.
When the report is complete, a link to the report file appears below the Generate Reports label.
Scheduling an IPS top N MVX-correlated report (Web UI)
To schedule an IPS top N MVX‑correlated report:
In the Web UI, choose Reports > Schedule.
In the Scheduled field, select the report frequency:
hourly
daily
weekly
monthly
In the Time fields, specify the report time.
If you selected a weekly report, specify the report day of the week in the WeekDay field.
If you selected a monthly report, specify the report day of the month in the MonthDay field.
In the Delivery field, select the report delivery method:
email—Deliver the report as a file attached to email. For information about configuring email notification, see the Network Security User Guide.
file—Deliver the report as a file linked from the Web UI.
In the Report Type field, select IPS Top N MVX Correlated.
In the Report Format field, select the report output format.
pdf—Write the report to an Adobe PDF file.
csv—Write the report to a CSV file.
In the Top field, select the number of attacks to be reported. Valid range is 1 ‑ 100.
In the Interface field, select the monitoring interfaces to be reported.
In the Time frame field, select the period of time that the report is to cover.
past day—The past 24 hours.
past week—The past 7 days.
past month—The past 1 month.
between—Between the From and To dates and times you specify.
Click Schedule Report. The page confirms receipt of your request.
When the report is complete, a link to the report file appears below the Generate Reports label.