IDS/IPS Activity Reports

To search for and generate a report on all attack activities from IDS/IPS systems, use the IDS/IPS Activity Real-Time Report.

Menu path: Reports > Threat Management > IDS/IPS Activity

For this report, you can select to view various options in the generated report for your Appliance. Optional filter operators can be sorted in Ascending or Descending order. Choose sort order using the list. The default is to display only Log Source IP, Source IP, Destination IP, Destination Port, Signature, and Count.

For information on saving the generated report, see Formats for Saving a Generated Report.

IDS/IPS Activity Report - Optional Filter Operators
Option Description
Log Source IP IP address of the device that sent these log messages
Source IP IP address from which the attack originated
Source Port Port from which the attack originated
Destination IP IP address that was targeted
Destination Port Port that was targeted
Action Response of the intrusion prevention system (IPS) when it detects an attack reported by the IDS/IPS
Note: If you do not have an IPS associated with your IDS/IPS, you might not see any results if using this filter.
Signature ID Rule or numeric ID for the event
Note: The Signature ID from the vendor might be more consistent than the Signature.
Protocol Protocol of the destination device
Signature Identifier from IDS/IPS for an event
Sensor Device that sends events to a collector analysis system
Sensor IP IP address of the device that detected the event
Classification Type of attack
Priority Priority level of the attack
Count Number of attacks.