ESA provides the DDoS Analytics and Attack Details dashboards to monitor service health, investigate attacks, and fine-tune mitigation policies. View statistics from the last 30 days for network-layer and application-layer attacks.
This feature is available only to Enterprise subscribers.
Analytics dashboard
The DDoS Analytics tab shows traffic patterns to help you distinguish legitimate usage from malicious activity. Filter by time range, up to 30 days.
Network layer (L3/L4) metrics
These metrics identify volumetric attacks that saturate network capacity.
-
Bandwidth (bits per second, bps): Measures attack traffic volume. A high bps value indicates a flood attack consuming available network bandwidth. When attack traffic exceeds 95% of bandwidth capacity, legitimate traffic delivery is disrupted.
-
Packet rate (packets per second, pps): Measures packet volume. A high pps value, even with low bandwidth (> 1 M), can indicate an attack exhausting server and network hardware processing capacity.
Analyzing both metrics reveals the attack signature. Large-packet floods show high bps and low pps; connection floods show low bps and high pps. If either metric is missing, mitigation policies may fail — without pps monitoring, low-bandwidth high-intensity attacks that exhaust protocol stack resources go undetected.
To view bps and pps data:
-
In the ESA console, choose Websites, and in the Website column, click the target website.
-
In the left navigation pane, choose .
-
On the DDoS page, click the DDoS Analytics tab, and then click the Network Layer (L3/4) tab.
-
In the time filter section, select a time range. The console displays detailed Network Layer (L3/4) traffic for the selected time range. ESA also provides statistics for the Peak Attack Bandwidth and Peak Attack Packet Rate within that range.
Application layer (L7) metrics
Queries per second (QPS): The number of HTTP/HTTPS requests received per second. QPS is the key metric for detecting Layer 7 attacks. Unlike network-layer attacks that spike bps or pps, Layer 7 attacks mimic normal users and appear as a sudden QPS surge — a sign of an HTTP flood draining CPU and memory.
To view QPS data:
-
In the ESA console, choose Websites, and in the Website column, click the target website.
-
In the left navigation pane, choose .
-
On the DDoS page, click the DDoS Analytics tab, and then click the Application Layer (L7) tab.
-
In the time filter section, select a time range. The console displays detailed Application Layer (L7) traffic for the selected time range. ESA also provides statistics for the Peak Traffic During HTTP Traffic Scrubbing and Peak Traffic During HTTPS Traffic Scrubbing within that range.
Traffic scrubbing events
During a large-scale DDoS attack, ESA performs traffic scrubbing — real-time filtering that separates malicious traffic from legitimate requests and discards attack packets. Only clean traffic reaches your origin server. Different attack types trigger scrubbing at different layers:
-
Network layer scrubbing events: Triggered when an attack reaches 5 Gbps or more.
-
Application layer scrubbing events: ESA uses deep learning on domain access QPS baselines and origin server status codes to detect anomalies, then scrubs traffic proportional to your service scale.
To view scrubbing event records:
-
In the ESA console, choose Websites, and in the Website column, click the target website.
-
In the left navigation pane, choose .
-
On the DDoS page, click the DDoS Analytics tab. As needed, you can click the Network Layer (L3/4) or Application Layer (L7) tab. Scroll to the bottom of the page to view the details of scrubbing events.
Attack details
The Attack Details tab logs all detected and mitigated DDoS attacks. Filter by time and attack type to investigate specific incidents. Use this view to:
-
Identify attack type trends targeting your website.
-
Review peak attack magnitudes.
-
Correlate attacks with other infrastructure incidents.
To view attack details:
-
In the ESA console, choose Websites, and in the Website column, click the target website.
-
In the left navigation pane, choose .
-
On the DDoS page, click the Attack Details tab. From the drop-down lists, select an attack type and a time range to view the Volumetric Attack Peak, Web Resource Exhaustion Attack, Connection Flood Attack Peak, and attack event details.