Forum Discussion
DDOS attack event ID
First, create a DoS protection profile using the desired thresholds, attack detection and mitigation methods and operation mode (blocking or transparent), and assign it to your virtual server. Then you will need to create a logging profile with DoS Protection enabled and then assign it to the VS also. DoS events will be listed as they are detected. Does this help?
- RozhJul 22, 2020
Nimbostratus
Thanks Erik .
I know which One event causes DDOS attack, I also have Syslog of F5 and I receive on my SIEM. In fact I want to create a dashboard on the SIEM, now I need to know which One event id cause the DDOS trafic that by filtering On the received logs, I can reach my goal.
i need log reference with event id.
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com