jack_10574
Aug 02, 2016Nimbostratus
F5 AFM Reporting --> Dos overview
Hi all
i have go through the AFM security --> Reporting --> DOS --> network . I found some log here but i am not understand how the log are trigger . Can anyone explain to me base on the screen shoot what is the meaning virtual server = aggregate ? what means aggregate for virtual server ?
just to note , in Dos profile i am set detection threshold = 1000 pps individually for TCP RST flood and UDP =1000 pps as well.. but every attack ID are showing number with less than 100 ... Isnt it only trigger when more than 1000 pps ?
please advice