All Products
Search
Document Center

Anti-DDoS:Query system logs

Last Updated:Mar 31, 2026

The System Logs page lets you review billing and event records for up to 90 days. The following log types are available:

Log typeWhat it showsPrerequisites
Burstable clean bandwidth billsDaily or monthly 95th percentile usage and chargesInstance purchased; burstable clean bandwidth enabled
Burstable Queries Per Second (QPS) billsDaily or monthly 95th percentile QPS usage and chargesInstance purchased; burstable QPS enabled
Alerts on exceeded upper limitsEvents where service bandwidth, new connections, or concurrent connections exceeded instance limitsInstance purchased
Destination rate limit eventsEvents where destination rate limiting was triggeredInstance purchased

Query bills for burstable clean bandwidth

Prerequisites

Before you begin, ensure that you have:

Bill generation and settlement times

Metering methodBill available on System LogsFee deducted
Daily 95th percentile14:00 on the next day; email notification sent17:00 on the next day
Monthly 95th percentile10:00 on the first day of the next month; email notification sent10:00 on the third day of the next month

Log entry fields

Each bill entry includes the following fields.

Description column

Metering methodFieldValue
Monthly 95th percentileThe peak trafficPeak service traffic in the current month
The bandwidth that exceeds the clean bandwidthDifference between the peak service traffic and the clean bandwidth of the instance on the last day the feature was enabled in that calendar month
The usage of the burstable clean bandwidthDifference between the monthly 95th percentile bandwidth and the clean bandwidth of the instance on the last day the feature was enabled. See Billing of the burstable clean bandwidth feature for the calculation method.
Daily 95th percentileThe peak trafficPeak 95th percentile bandwidth within the calendar day
The bandwidth that exceeds the clean bandwidthDifference between the peak 95th percentile bandwidth and the clean bandwidth of the instance on that calendar day
The usage of the burstable clean bandwidthDifference between the daily 95th percentile bandwidth and the clean bandwidth on that calendar day. See Billing of the burstable clean bandwidth feature for the calculation method.

Status column

StatusMeaningWhat to do
Pending for BillingUsage is collected but the bill has not been generated yet.Click View in the Details column to review actual service traffic. If the amount differs from your actual usage, open aticket. If confirmed, the bill status changes to Billing Terminated and no payment is required.
BilledThe bill is generated based on actual usage, and the fee has been deducted from your account balance.Make sure your account has sufficient balance. An overdue payment suspends all pay-as-you-go services.
Billing TerminatedBilling for this period is terminated.No payment required.

Query burstable clean bandwidth bills

  1. Log in to the Anti-DDoS Pro console.Anti-DDoS Pro console

  2. In the top navigation bar, select the region of your instance:

    • Anti-DDoS Proxy (Chinese Mainland): select Chinese Mainland for Anti-DDoS Pro instances.

    • Anti-DDoS Proxy (Outside Chinese Mainland): select Outside Chinese Mainland for Anti-DDoS Premium instances.

  3. In the left-side navigation pane, choose Investigation > System Logs.

  4. On the System Logs page, select Monthly 95th Percentile of Burstable Clean Bandwidth or Daily 95th Percentile of Burstable Clean Bandwidth. Specify the IP address and time range, then click the image..png icon.

Query bills for burstable QPS

Prerequisites

Before you begin, ensure that you have:

Bill generation and settlement times

Metering methodBill available on System LogsFee deducted
Daily 95th percentile10:00 on the next day; email notification sent16:00 on the next day
Monthly 95th percentile11:00 on the first day of the next month; email notification sent11:00 on the third day of the next month

Log entry fields

Each bill entry includes the following fields.

Description column

Metering methodFieldValue
Daily 95th percentileThe peak QPSPeak 95th percentile QPS within the calendar day
The QPS that exceeds the clean QPSDifference between the peak 95th percentile QPS and the clean QPS of the instance on that calendar day
The usage of the burstable QPSDifference between the daily 95th percentile QPS and the clean QPS on that calendar day
Monthly 95th percentileThe peak QPSActual peak service QPS in the current month
The QPS that exceeds the clean QPSDifference between the actual peak service QPS and the clean QPS of the instance on the last day the feature was enabled in that calendar month
The usage of the burstable QPSDifference between the monthly 95th percentile QPS and the clean QPS on the last day the feature was enabled

Status column

StatusMeaningWhat to do
Pending for BillingUsage is collected but the bill has not been generated yet.Click View in the Details column to review actual service QPS. If the amount differs from your actual usage, contact Intelligent Customer Service. If confirmed, the bill status changes to Billing Terminated and no payment is required.
BilledThe bill is generated based on actual usage, and the fee has been deducted from your account balance.Make sure your account has sufficient balance. An overdue payment suspends all pay-as-you-go services.
Billing TerminatedBilling for this period is terminated.No payment required.

Query burstable QPS bills

  1. Log in to the Anti-DDoS Pro console.Anti-DDoS Pro console

  2. In the top navigation bar, select the region of your instance:

    • Anti-DDoS Proxy (Chinese Mainland): select Chinese Mainland for Anti-DDoS Pro instances.

    • Anti-DDoS Proxy (Outside Chinese Mainland): select Outside Chinese Mainland for Anti-DDoS Premium instances.

  3. In the left-side navigation pane, choose Investigation > System Logs.

  4. On the System Logs page, select Monthly 95th Percentile of Burstable QPS or Daily 95th Percentile of Burstable QPS. Specify the IP address and time range.

Query alerts on exceeded upper limits

An alert is generated when service traffic, new connections, or concurrent connections exceed the upper limit of your instance specification.

Prerequisites

Before you begin, ensure that you have an Anti-DDoS Pro or Anti-DDoS Premium instance. See Purchase an Anti-DDoS Pro or Anti-DDoS Premium instance.

Query exceeded-limit alerts

  1. Log in to the Anti-DDoS Pro console.Anti-DDoS Pro console

  2. In the top navigation bar, select the region of your instance:

    • Anti-DDoS Proxy (Chinese Mainland): select Chinese Mainland for Anti-DDoS Pro instances.

    • Anti-DDoS Proxy (Outside Chinese Mainland): select Outside Chinese Mainland for Anti-DDoS Premium instances.

  3. In the left-side navigation pane, choose Investigation > System Logs.

  4. On the System Logs page, select Alerts on Exceeded Upper Limits. Specify the IP address and time range.

Each alert entry shows the instance IP address and the event type (service bandwidth, new connections, or concurrent connections) in the Description column. Click View in the Details column to see the full alert details.

Query destination rate limit events

Prerequisites

Before you begin, ensure that you have an Anti-DDoS Pro or Anti-DDoS Premium instance. See Purchase an Anti-DDoS Pro or Anti-DDoS Premium instance.

Query rate limit events

  1. Log in to the Anti-DDoS Pro console.Anti-DDoS Pro console

  2. In the top navigation bar, select the region of your instance:

    • Anti-DDoS Proxy (Chinese Mainland): select Chinese Mainland for Anti-DDoS Pro instances.

    • Anti-DDoS Proxy (Outside Chinese Mainland): select Outside Chinese Mainland for Anti-DDoS Premium instances.

  3. In the left-side navigation pane, choose Investigation > System Logs.

  4. On the System Logs page, select Destination Rate Limit Events. Specify the IP address and time range.

Click View in the Details column to see the full details of an event.

What's next