Anti-DDoS Native integrates with CloudMonitor to send you alert notifications for traffic on your assets, blackhole filtering events, and scrubbing events. This helps you quickly detect anomalies, reduce response times, and restore your services. This topic describes how to configure CloudMonitor alert notifications.
Supported alert types
-
IP traffic alerts: Create alerts for inbound and outbound traffic on an asset. The traffic is measured in bits per second (bps) and packets per second (pps).
-
DDoS blackhole filtering event alerts: Create alerts for the start and end of blackhole filtering events from Anti-DDoS Native.
-
DDoS scrubbing event alerts: Create alerts for the start and end of scrubbing events from Anti-DDoS Native.
Configure CloudMonitor alerts
Log on to the Traffic Security console,In the left-side navigation pane, choose DDoS.
In the left-side navigation pane, choose .
-
On the CloudMonitor Alerts page, click CloudMonitor Notification in the Interaction Configuration column to open the CloudMonitor console.
-
In the CloudMonitor console, configure alert contacts and alert contact groups.
NoteYou can send alert notifications only to alert contact groups. If you have already created one, skip this step.
-
In the left-side navigation pane, choose .
-
On the Alert Contacts tab, click Create Alert Contact. In the Set Alert Contact panel, enter the contact information, complete the slider verification, and then click OK.
-
On the Alert Contact Group tab, click Create Alert Contact Group. In the Create Alert Contact Group panel, enter the required information, select contacts, and then click Confirm.
-
-
Create alert notifications.
-
IP traffic alerts
-
In the left-side navigation pane, choose and click Create Alert Rule.
-
On the Create Alert Rule tab, configure the parameters.
-
Product: Select ddosbgp.
-
Rule Description: Click Add Rule. In the panel, configure the following parameters and click OK.
Parameter
Description
Alert Rule
Enter a name for the rule.
Metric Type
-
Simple Metric: Select a metric, then set its threshold and alert level.
-
Combined Metrics: Select an alert level, then define an alert condition using two or more metrics.
NoteMulti-metric alert rules require the target resource to report data for every included metric. For example, if the rule includes a public network metric but the ECS instance has no public IP address, the alert does not trigger.
-
Expression: Select an alert level, then define an alert expression.
-
Dynamic Threshold: Smart threshold details: Overview | Create a smart threshold alert rule.
Metric
If you set Metric Type to Simple Metric or Combined Metrics, you must specify a Metric.
Set the alert threshold to 1.5 times your normal traffic volume. For example, if your normal inbound traffic rate is 200 Mbps, you can configure an alert to trigger if the inbound traffic rate exceeds 300 Mbps for three consecutive detection cycles.
You can create alerts for the following metrics:
-
PacketRateIn
-
PacketRateOut
-
TrafficRateIn
-
TrafficRateOut
When you receive an alert, go to the Mitigation Logs page to analyze service data and determine if an attack occurred. Based on this analysis, you can adjust your configuration on the Mitigation Settings page.
-
For more information about the parameters, see Create an alert rule.
-
-
-
DDoS blackhole filtering event alerts and DDoS scrubbing event alerts
-
On the page, click Save as Alert Rule.
-
On the Create/Modify Event-triggered Alert Rule page, configure the alert rule.
-
Product Type: Select ddosbgp.
-
Event Type: Select DDoS Attacks.
-
Event Level: Select the event level for which you want to receive notifications. All DDoS alert events are of the CRITICAL level. You can select only CRITICAL.
-
Event Name: Available values are ddosbgp_event_blackhole and ddosbgp_event_clean.
For more information about the parameters, see Manage system event-triggered alert rules (Old). When you receive an alert, go to the Mitigation Logs and Attack Analysis pages to analyze service data and determine if an attack occurred. Based on this analysis, you can adjust your configuration on the Mitigation Settings page.
-
-
-
Related documents
-
To deactivate blackhole filtering for an asset protected by Anti-DDoS Native, see Deactivate blackhole filtering.
-
To configure mitigation policies, see Mitigation Settings.