The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Next Generation default reports

Prev Next

The Next Generation default report options are available as follows:

Host Event reports
Report Name Description
Default - Attack Destination Reputation Summary A list of attack destinations
Default - Attack Source Reputation Summary A summary of Source reputation
Alert Information reports
Report Name Description
Default - Layer 7 Data List of attacks and their corresponding L7 data (such as HTTP URL, FTP filename and SMTP sender/recipient)
Default - New Attacks List of new attacks detected only during the selected time period. Following are the highlights of this report:
  • Attacks that are acknowledged and marked for deletion are not included in the list.
  • The report is available in only table format.
Default - Quarantine History List of hosts in quarantine because they have attempted an intrusion
Default - Telemetry (Insights Security Posture) This report is for feature telemetry information the Manager is sending to the Trellix Insights when Insights integration is enabled.

Note

This information is used to derive the security posture score on Trellix Insights.

Default - Telemetry (Trellix) The information the Manager is sending to the Trellix corporate team when telemetry is enabled.
Default - Telemetry (IPS/Insights) The information the Manager is sending to the Trellix IPS product team and Trellix Insights team when telemetry is enabled.
Default - Top 10 Attack Source Countries Information on the top 10 source countries in the root admin domain
Default - Top 10 Attacks The top 10 attacks by attack count for all the devices in the network. The report displays the following fields:
  • Attack Name - The name of the attack
  • Attack Count - The number of times a particular attack was detected for a single alert instance
Default - Top 10 Malware Detections Information on the top 10 malware detections
Default - Top Attack Destinations Information on the top 10 attack destination
Default - Top Attack Sources Information on the top 10 attack sources

Applications-related reports

For any Applications-related report to show data, you must enable Application Identification on the required Monitoring ports for the time period that you query. For example, if you want to run the Top 10 Application Categories by Attack Count report for the traffic monitored between 9 am and 10 am today, you must have enabled Application Identification on the corresponding monitoring ports between 9 am and 10 am today based on the Manager server's clock.

Reports and Descriptions
Report Name Description
Default - Top 10 Application Categories by Attack Count Run this report to view the top 10 Categories based on the attacks generated per category. Like other Next Generation reports, this too displays information in graphical and tabular formats. The following are the information that you can find in this report:
  • For each of the top 10 categories, the bandwidth consumed, the number of flows, and the number of attacks generated per category.
  • The applications detected for each of the top 10 categories. For example, if web mail is one of the top 10 categories, it lists all the web mail applications that were detected. If an application belongs to multiple categories within the top 10, it is listed under each of those categories.
  • For each application, the bandwidth consumed, the number of flows, and the number of attacks generated.
Default - Top 10 Application Categories by Bandwidth Usage This report is similar to the Top 10 Application Categories by attack count except that the details are based on the bandwidth consumed.
Default - Top 10 Application Categories by Connection Count This report is similar to the Top 10 Application Categories by attack count except that the details are based on the number of connections or flows.
Default - Top 10 Applications by Attack Count Run this report to view the top 10 Applications based on the number of attacks that each application was involved. The following are the information that you can find in this report:
  • Risk— Whether the application is high, medium, or low risk. Trellix Labs categorizes an application based on its vulnerability and the probability for it to deliver malware.
  • Bandwidth— The network bandwidth consumed by each application.
  • Connection count— The number of flows per application.
  • Attack count— The number of attacks that each application was involved. This report is sorted based on the attack count.
Default - Top 10 Applications by Bandwidth Usage for All Risk Levels This report is similar to the Top 10 Applications by attack count except that it is based on the bandwidth consumed by each application.
Default - Top 10 Applications by Bandwidth Usage for Each Risk Level This report provides the top 10 applications in each risk category based on the bandwidth consumed per application. That is, it lists the top 10 high-risk applications based on bandwidth consumed by each of those applications. Similarly, it lists the top 10 medium and low-risk applications in separate tables.
Default - Top 10 Applications by Connection Count This report is similar to the Top 10 Applications by attack count except that it is based on the number of connections per application.

Note

For the applications-related reports to show data, you must enable Application Identification.

The Default Next Generation reports show information from all the Sensors for which you have enabled Application Identification. To view the details from specific Sensors, you can generate a Next Generation Duplicate report or a Next Generation User Defined Report.

Device Performance - Hourly reports
Report Name Description
Default - High Device TCP / UDP Flow Usage Status of TCP/UDP flow utilization
Default - High Device Throughput Usage Status of Sensor throughput utilization threshold
NTBA Data Query reports
Report Name Description
Default - Top Files Accessed This report shows the most accessed files in the network during the selected period.
Default - Top Most Recently-Active Endpoints This report shows the endpoints most recently active on the network.
Default - Top Endpoint Summary This report shows the summary detail for endpoints in the network during the selected period.
Default - Top Endpoints by Bandwidth Usage This report shows endpoints sending/receiving the most bytes in the network during the selected period.
Default - Top Endpoints by GTI Reputation This report shows the endpoints with the Highest GTI Reputation in the network during the selected period.
Default - Top Endpoints by Threat Factor This report shows the endpoints sorted by Threat Factor during the selected period.
Default - Top New Applications Seen This report shows the applications that are new on the network during the selected period.
Default - Top New Services Seen This report shows services that are new on the network during the selected period.
Default - Top New Endpoints Seen This report shows the endpoints that are new on the network during the selected period.
Default - Top Services by Bandwidth Usage This report shows services consuming the most bandwidth (bytes) in the network during the selected period.
Default - Top Applications by Bandwidth Usage This report shows applications consuming the most bandwidth (bytes) in the network during the selected period.
Default - Top Most Recent Connections This report shows connection summary in the network during the selected period.
Default - Top 10 Exporter Interfaces This report lists the Exporter interfaces that were high on traffic during the selected period.
Default - Top 10 Conversations This report lists conversations that were high on traffic during the selected time period. The report displays the following fields:
  • Source IP Address - IP address of the source host
  • Destination IP Address - IP address of the destination host
  • Service Name - Name of the service used by the conversation
  • In Bytes - Inbound traffic in bytes
  • Out Bytes - Outbound traffic in bytes
  • Total Bytes - Total traffic in bytes
  • Utilization % - Bandwidth utilization percentage
Default - Top 10 Endpoint Executables This report lists conversations that were high on traffic during the selected time period.
Default - Endpoint Executable Details This report shows the details of all the executables on the network during the selected time period.