Overview
Monitoring’s DDoS prevention module analyzes traffic patterns and automatically mitigates volumetric and application-layer attacks before they reach protected workloads. The module operates in two modes: Monitor (detection only) and Mitigate (automatic blocking).Prerequisites
- Administrator credentials with the
adminrole - Network flow collection configured (see Agent Configuration)
- Baseline traffic patterns established (minimum 72 hours of Monitor mode data recommended)
Configuring DDoS Protection Policy
Navigate to DDoS Protection
Navigate to Monitor Center > Monitoring (DDoS Policies, admin view).
Configure detection settings
Add whitelist entries
Add IP ranges that should never be blocked regardless of traffic volume:
- Monitoring system IPs (prevent self-blocking)
- Partner or customer IP ranges with legitimate high-volume traffic
- Internal automation systems
Switch to Mitigate mode
After at least 72 hours of Monitor mode with no false positives:
- Review the alert history for any false positive detections
- Add any flagged legitimate sources to the whitelist
- Switch the policy to Mitigate mode
Policy shows Mitigate mode active. Check the DDoS Events feed to confirm no legitimate traffic is being blocked.
Reviewing DDoS Events
- Dashboard
- CLI
Navigate to Monitor Center > Monitoring (DDoS Events, admin view) to review detected and
mitigated attacks:
Handling False Positives
If a legitimate source is incorrectly blocked:Identify the blocked source
Check if a specific IP is blocked
Unblock the source
Unblock a specific source
Add to whitelist to prevent future blocks
Navigate to Monitor Center > Monitoring (DDoS Whitelist, admin view) and add the IP range
of the legitimate source with a descriptive comment.
Source is unblocked and whitelist entry prevents future false positives.
Next Steps
Network Monitoring (User Guide)
User-level network traffic analysis for attack investigation
Alert Channels
Configure notification channels for DDoS detection events
Security
Overall Monitoring security configuration including access control
Troubleshooting
Diagnose false positive blocks and detection threshold tuning
