Forum Discussion
F5 AFM Reporting --> Dos overview
Hi all
i have go through the AFM security --> Reporting --> DOS --> network . I found some log here but i am not understand how the log are trigger . Can anyone explain to me base on the screen shoot what is the meaning virtual server = aggregate ? what means aggregate for virtual server ?
just to note , in Dos profile i am set detection threshold = 1000 pps individually for TCP RST flood and UDP =1000 pps as well.. but every attack ID are showing number with less than 100 ... Isnt it only trigger when more than 1000 pps ?
please advice
2 Replies
- jgranieri
Nimbostratus
Thats interesting because i have fine tuned dos settings and my AFM DoS reporting doesn't show anything. do you happen to have a test VIP thats hitting this thresholds?
Can you drill down on one of the attack ID's to get more information... the chart you have displayed is the top total requests, did the PPS detect threshold get triggered?
- Deep_287674
Nimbostratus
We need clarification because I also see nothing when I visit ecurity --> Reporting --> DOS --> network. My Threshhold 500pps rate limit 100000pps
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com