Anomaly/Attack Situation

Function

This function enables you to view the situation of various anomalies or attacks.

Parameter

Table 1 Anomaly/Attack situation query parameters
Parameter Description

Direction

Select Inbound or Outbound the drop-down list.
Device

Select a device from the drop-down list.

Zone Click , select a Zone on the Zone page that is displayed, and then click OK.
Traffic type

Select Attack or Abnormal from the drop-down list.

IP Address Enter the destination IP address. Both IPv4 and IPv6 addresses are applicable. The anomaly/attack traffic destined for the IP address is queried.
Time Click to select the start time and end time of statistics. Or you can change the time values in corresponding text boxes.

The end time should be later than the start time and the interval cannot be longer than one year.

Example

Set the device to DDoS-Cleaning and zone to All. Figure 1 shows the trend diagram and list of anomalies/attacks queried within a specified time range.

Figure 1 Anomaly/Attack situation

Procedure

  1. Choose Report > Report > Anomaly/Attack Analysis.
  2. Click the Anomaly/Attack situation tab.
  3. Set query parameters.
  4. Click Search.

    The situation of anomalies or attacks that meet the query conditions is displayed.

  5. Optional: Open or save the query results as files, or send queried reports to the specified email address.

    • Click to open or save the query results as PDF files. A maximum of 10,000 entries can be displayed.
    • Click to open or save the query results as EXCEL files. A maximum of 10,000 entries can be displayed.
    • Click to open or save the query results as CSV files. All data except figures can be displayed.
    • Click to enter a recipient mail address and select an attachment format. Then click OK.


Copyright © Huawei Technologies Co., Ltd.