The Next Generation default report options are available as follows:
| Report Name | Description |
|---|---|
| Default - Attack Destination Reputation Summary | A list of attack destinations |
| Default - Attack Source Reputation Summary | A summary of Source reputation |
| Report Name | Description |
|---|---|
| Default - Layer 7 Data | List of attacks and their corresponding L7 data (such as HTTP URL, FTP filename and SMTP sender/recipient) |
| Default - New Attacks | List of new attacks detected only during the selected time period. Following are the highlights of this report:
|
| Default - Quarantine History | List of hosts in quarantine because they have attempted an intrusion |
| Default - Telemetry (Insights Security Posture) | This report is for feature telemetry information the Manager is sending to the
Trellix Insights when Insights integration is enabled.
|
| Default - Telemetry (Trellix) | The information the Manager is sending to the Trellix corporate team when telemetry is enabled. |
| Default - Telemetry (IPS/Insights) | The information the Manager is sending to the Trellix IPS product team and Trellix Insights team when telemetry is enabled. |
| Default - Top 10 Attack Source Countries | Information on the top 10 source countries in the root admin domain |
| Default - Top 10 Attacks | The top 10 attacks by attack count for all the devices in the network. The report displays the following fields:
|
| Default - Top 10 Malware Detections | Information on the top 10 malware detections |
| Default - Top Attack Destinations | Information on the top 10 attack destination |
| Default - Top Attack Sources | Information on the top 10 attack sources |
Applications-related reports
For any Applications-related report to show data, you must enable Application Identification on the required Monitoring ports for the time period that you query. For example, if you want to run the Top 10 Application Categories by Attack Count report for the traffic monitored between 9 am and 10 am today, you must have enabled Application Identification on the corresponding monitoring ports between 9 am and 10 am today based on the Manager server's clock.
| Report Name | Description |
|---|---|
| Default - Top 10 Application Categories by Attack Count | Run this report to view the top 10 Categories based on the attacks generated per category. Like other Next Generation reports, this too displays information in graphical and tabular formats. The following are the information that you can find in this report:
|
| Default - Top 10 Application Categories by Bandwidth Usage | This report is similar to the Top 10 Application Categories by attack count except that the details are based on the bandwidth consumed. |
| Default - Top 10 Application Categories by Connection Count | This report is similar to the Top 10 Application Categories by attack count except that the details are based on the number of connections or flows. |
| Default - Top 10 Applications by Attack Count | Run this report to view the top 10 Applications based on the number of attacks that each application was involved. The following are the information that you can find in this report:
|
| Default - Top 10 Applications by Bandwidth Usage for All Risk Levels | This report is similar to the Top 10 Applications by attack count except that it is based on the bandwidth consumed by each application. |
| Default - Top 10 Applications by Bandwidth Usage for Each Risk Level | This report provides the top 10 applications in each risk category based on the bandwidth consumed per application. That is, it lists the top 10 high-risk applications based on bandwidth consumed by each of those applications. Similarly, it lists the top 10 medium and low-risk applications in separate tables. |
| Default - Top 10 Applications by Connection Count | This report is similar to the Top 10 Applications by attack count except that it is based on the number of connections per application. |
Note
For the applications-related reports to show data, you must enable Application Identification.
The Default Next Generation reports show information from all the Sensors for which you have enabled Application Identification. To view the details from specific Sensors, you can generate a Next Generation Duplicate report or a Next Generation User Defined Report.
| Report Name | Description |
|---|---|
| Default - High Device TCP / UDP Flow Usage | Status of TCP/UDP flow utilization |
| Default - High Device Throughput Usage | Status of Sensor throughput utilization threshold |
| Report Name | Description |
|---|---|
| Default - Top Files Accessed | This report shows the most accessed files in the network during the selected period. |
| Default - Top Most Recently-Active Endpoints | This report shows the endpoints most recently active on the network. |
| Default - Top Endpoint Summary | This report shows the summary detail for endpoints in the network during the selected period. |
| Default - Top Endpoints by Bandwidth Usage | This report shows endpoints sending/receiving the most bytes in the network during the selected period. |
| Default - Top Endpoints by GTI Reputation | This report shows the endpoints with the Highest GTI Reputation in the network during the selected period. |
| Default - Top Endpoints by Threat Factor | This report shows the endpoints sorted by Threat Factor during the selected period. |
| Default - Top New Applications Seen | This report shows the applications that are new on the network during the selected period. |
| Default - Top New Services Seen | This report shows services that are new on the network during the selected period. |
| Default - Top New Endpoints Seen | This report shows the endpoints that are new on the network during the selected period. |
| Default - Top Services by Bandwidth Usage | This report shows services consuming the most bandwidth (bytes) in the network during the selected period. |
| Default - Top Applications by Bandwidth Usage | This report shows applications consuming the most bandwidth (bytes) in the network during the selected period. |
| Default - Top Most Recent Connections | This report shows connection summary in the network during the selected period. |
| Default - Top 10 Exporter Interfaces | This report lists the Exporter interfaces that were high on traffic during the selected period. |
| Default - Top 10 Conversations | This report lists conversations that were high on traffic during the selected time period. The report displays the following fields:
|
| Default - Top 10 Endpoint Executables | This report lists conversations that were high on traffic during the selected time period. |
| Default - Endpoint Executable Details | This report shows the details of all the executables on the network during the selected time period. |