This topic describes how to view traffic scrubbing or blackhole filtering events of Alibaba Cloud assets within the last 90 days. The assets are assigned public IP addresses.
Usage notes
If your asset uses an IPv4 address, you can view event information for up to seven days. For assets with an IPv6 address, event information is available only for three hours. If the desired information exceeds these time limits, the View Details button will be dimmed and inaccessible.
If your asset is an Anycast EIP, the View Details button will also be dimmed and the information cannot be viewed.
Procedure
Log on to the Traffic Security console.
In the left-side navigation pane, click Event Center.
Enter the IP address of the asset, select the event type, asset type, and time range, and then click Search.
Column
Description
Attacked Asset IP
The public IP address of the asset that encounters the DDoS attack.
Asset Type
The type of the asset.
Threshold (bit/s)
The traffic scrubbing threshold in bit/s at which the traffic scrubbing event is triggered. Unit: Mbit/s.
Threshold (pps)
The traffic scrubbing threshold in packets per second (pps) at which the traffic scrubbing event is triggered.
Attack Time
The start time and end time of the DDoS attack.
Event Type
Traffic scrubbing: If the traffic scrubbing threshold in bit/s or pps is reached, traffic scrubbing is triggered. You can click Cancel Traffic Scrubbing to cancel traffic scrubbing. For more information, see Cancel traffic scrubbing.
Blackhole filtering: If the volume exceeds the maximum DDoS mitigation capability of an asset, blackhole filtering is triggered. For more information, see Blackhole filtering policy of Alibaba Cloud.
Optional. Click View Details in the Actions column to view the trend charts of Traffic and Inbound Traffic (pps).
NoteIf your asset is released, the message You cannot view traffic details because the asset is removed from the current account appears and you cannot view information about events.
You can click Download in the upper-right corner of the Event Center page to download the evidence of DDoS attacks.