The Business Monitoring page displays protection data for your Anti-DDoS Native instance, including traffic trends for protected assets and DDoS attack event logs, to help you monitor your service's security posture. This topic describes how to query this data and explains what is available.
Prerequisites
You have purchased an Anti-DDoS Native instance and added protected objects to the instance.
For more information, see Purchase an Anti-DDoS Native instance and Protected objects.
Background information
The Business Monitoring page displays data from June 3, 2021, onward. To query data from before this date, see Manage instances.
Query business monitoring data
Log on to the Traffic Security console,In the left-side navigation pane, choose DDoS.
In the left-side navigation pane, choose .
In the top navigation bar, select the resource group to which the instances belong and the region in which the instances reside.
Anti-DDoS Origin 1.0 (Subscription) instances: Select the region in which the instance resides.
Anti-DDoS Origin 2.0 (Subscription) and Anti-DDoS Origin 2.0 (Pay-as-you-go) instances: Select All Regions.
-
In the upper-left corner of the page, select the Anti-DDoS Native instance.
-
View the monitoring data for the instance. The page includes four main sections, which are described in the table below.
Type
Purpose
Actions
Description
Business statistics (①)
Displays historical peak protection data for the instance, including days of continuous protection, peak detected traffic (bps and pps), and peak mitigated attack traffic (bps and pps).
None.
Business traffic trends (②)
Shows inbound traffic trends for the public IP addresses protected by the Anti-DDoS Native instance. This includes trends for bandwidth (in bps) and packet rate (in pps).
Filter data by protected object and time range.
DDoS attack events (③)
Lists attack events against the instance, including traffic scrubbing and blackhole filtering events. From this section, you can analyze and manage these events.
-
Filter data by protected object and time range.
-
For a specific DDoS attack event, you can perform the following operations: Cancel Scrubbing, Download Packet Capture, and View Attack Analysis.
Attack trend analysis charts (④)
Shows the overall network attack trend on the Anti-DDoS Native instance over the past year. This data helps you assess business risks and security requirements.
Filter data by time range.
-
Business statistics
This section displays the following metrics:
-
Continuous Monitoring and Protection For: The number of consecutive days the instance has protected your services.
-
Detection Peak: The highest volume of inbound traffic detected by the instance since activation, measured in bits per second (bps) and packets per second (pps).
-
Mitigation Peak: The highest volume of attack traffic scrubbed by the instance since activation, measured in bps and pps.
Business traffic trends
This section contains the following charts:
-
Traffic (bps) peak trend chart: Shows the bandwidth trends (in bps) for the total inbound traffic, total outbound traffic, and attack traffic of a specified protected object (IP address).
-
Packets (pps) peak trend chart: Shows the packet rate trends (in pps) for the total inbound packets, total outbound packets, and attack packets of a specified protected object (IP address).
You can configure the following query parameters above this section:
-
Protected object: From the drop-down list, select All Protected Objects or a specific protected object (IP address) to view its data.
If you select All Protected Objects, you can click a data point on the trend chart to view the top 20 protected objects (IP addresses) with the highest traffic volume at that time.
-
Time range: Click Last 30 Minutes, Last Day, Last 7 Days, or Last 30 Days, or specify a custom time range to query the data.
If you specify a custom time range, the range must be within the last 30 days.
DDoS attack events
The attack event table records all attack events that have occurred on the Anti-DDoS Native instance. Each attack event record includes the following information: Attack Time, Event, Attacked IP Address, Triggered Attack Traffic (bit/s), Triggered Attack Traffic (pps), Peak Attack Traffic (bit/s), and Peak Attack Traffic (pps).
The following operations are supported for attack event records:
-
Cancel Scrubbing: This operation is available only for ongoing traffic scrubbing events. If you determine that a traffic surge is from legitimate business activity (such as a sales promotion) and not an attack, you can use this action to stop the scrubbing process.
-
Download Packet Capture: Downloads the packet capture file for the attack event. Use this file as evidence when reporting the incident to the relevant authorities.
-
View Attack Analysis: Displays detailed attack analysis data for the attack event. For more information about the analysis data, see Attack Analysis.
Use the Protected object and Time range filters above the Business traffic trends section to filter the attack event table.
Attack trend analysis
The attack trend analysis charts show the overall trend of network attacks on the Anti-DDoS Native instance over the past year. The following charts are included:
-
Attack Trend: Represents the trend of attack metrics for your Anti-DDoS Native instance, including the Traffic Scrubbing Sessions, Blackhole Event, IP Addresses Under Traffic Scrubbing, and IP Address Under Blackhole Filtering.
-
Peak Attack Throughput: Shows the trend of peak attack traffic (in bps) against the instance.
-
Attacked Duration: Shows the trend of attack durations, which are categorized into Less Than 10 Minutes, 10-30 Minutes, 30-120 Minutes, 2-10 Hours, and More Than 10 Hours.
In the top-right corner of this section, you can set the time range by clicking Last 1 Week, Last 1 Month, Last 3 Months, or Last 1 Year.