This topic covers the following information:
Report overview
Report prerequisites
Generating an IPS top N victims report (Web UI)
Scheduling an IPS top N victims report (Web UI)
Report overview
The Top N Victims report lists the specified number (1 through 100) of most-attacked victims found by IPS rules during the specifid reporting period:
Victim—IP address of a victim host found by IPS rules.
# of Rules Matched—Number of IPS rules that matched attacks on the victim.
You can request the report to be output as a PDF file or as a CSV file in the /data/reports folder on the local drive. The format of the report file name is ips_top_n_victim_hostName_dateCreated_timeCreated, where hostName is the host name assigned to your appliance, and dateCreated and timeCreated identify the date and time the report was created.
Note
If you need a report that lists victim hosts of MVX-correlated attacks detected by IPS rules, you can generate an IPS Top N MVX-Correlated report. Specify any value for N, from 1 through 100, and then view the report section titled op <n> Victims. See IPS top N MVX-correlated.
Report prerequisites
Log in to the Web UI of the IPS appliance as Monitor, Analyst, Operator, or Admin.
Generating an IPS top N victims report (Web UI)
To generate a report of the IPS top N victims:
In the Web UI, choose Reports > Reports.
In the Report Type field, select IPS Top N Victims.
In the Report Format field, select the report output format.
pdf—Write the report to an Adobe PDF file.
csv—Write the report to a CSV file.
In the Top field, select the number of attacks to be reported. Valid range is 1 ‑ 100.
In the Interface field, select the monitoring interfaces to be reported.
In the Time frame field, select the period of time that the report is to cover.
past day—The past 24 hours.
past week—The past 7 days.
past month—The past 1 month.
between—Between the From and To dates and times you specify.
Click Generate Report. The page confirms receipt of your request.
When the report is complete, a link to the report file appears below the Generate Reports label.
Scheduling an IPS top N victims report (Web UI)
To schedule a report of the IPS Top N Victims:
In the Web UI, choose Reports > Schedule.
In the Scheduled field, select the report frequency:
hourly
daily
weekly
monthly
In the Time fields, specify the report time.
If you selected a weekly report, specify the report day of the week in the WeekDay field.
If you selected a monthly report, specify the report day of the month in the MonthDay field.
In the Delivery field, select the report delivery method:
email—Deliver the report as a file attached to email. For information about configuring email notification, see the Network Security User Guide.
file—Deliver the report as a file linked from the Web UI.
In the Report Type field, select IPS Top N Victims.
In the Report Format field, select the report output format.
pdf—Write the report to an Adobe PDF file.
csv—Write the report to a CSV file.
In the Top field, select the number of attacks to be reported. Valid range is 1 ‑ 100.
In the Interface field, select the monitoring interfaces to be reported.
In the Time frame field, select the period of time that the report is to cover.
past day—The past 24 hours.
past week—The past 7 days.
past month—The past 1 month.
between—Between the From and To dates and times you specify.
Click Generate Report. The page confirms receipt of your request.
When the report is complete, a link to the report file appears below the Generate Reports label.