Event Center
Scenario
During routine network security O&M, enterprises must continuously monitor the security status of their network traffic. CFW features an Event Center that provides a consolidated dashboard of protection statistics compiled over the past 7 days. This dashboard tracks inbound and outbound Internet traffic and VPC border traffic that has been inspected by your attack defense engines (including IPS, Reverse Shell, Sensitive Directory Scanning, and Antivirus). This visibility helps you monitor traffic security posture in real time and rapidly fine-tune your protection configurations.
This section describes how to use the Event Center to view and analyze attack defense metrics.
Notes and Constraints
- Intrusion prevention does not support decryption detection and defense for TLS- and SSL-encrypted traffic.
- There is a delay in collecting statistics in the Attacks module. The value varies according to the query time range. For details, see Table 1. If you need to query real-time data, you are advised to use Log Query.
Table 1 Attack trend time range parameters Time Range
Calculation Logic
Last 1 hour
Take the average value from the preceding 1-minute interval, rounded to the nearest minute. For example, if a query is run at 08:45:59, data is collected from 07:45:00 to 08:45:00.
Last 24 hours
Take the average value of the preceding 5-minute interval, rounded down to the nearest multiple of 5 minutes. For example, if a query is run at 2026/06/30 08:48:59, data is collected from 2026/06/29 08:45:00 to 2026/06/30 08:45:00.
Last 7 days
Take the average value of the preceding 1-hour interval, rounded to the nearest hour. For example, if a query is run at 2026/06/30 08:45:59, data is collected from 2026/06/23 08:00:00 to 2026/06/30 08:00:00.
Custom
- 5 minutes to 6 hours: Take the 1-minute average value, matching the logic of the Last 1 hour range.
- 6 hours (inclusive) to 3 days: Take the 5-minute average value, matching the logic of the Last 24 hours range.
- 3 days (inclusive) to 7 days (inclusive): Take the 30-minute average value, following a similar aggregation method to the Last 7 days range.
Viewing Attack Events
To view attack events, perform the following operations.
Viewing Internet Border Attacks
- Enable EIP protection, and ensure that existing traffic passes through the EIP. Configure the attack defense function.
For details about how to enable EIP protection, see Enabling Internet Border Traffic Protection. For details about how to configure attack defense, see Attack Defense.
- Log in to the CFW console.
- Click
in the upper left corner of the management console and select a region or project. - (Optional) Switch to another firewall instance. If there are multiple firewall instances, you can select a desired instance from the drop-down list in the upper left corner of the page.
- In the navigation pane on the left, choose . The Internet Borders tab is displayed by default.
- Select a protection border.
- View attack events detected by the Internet border firewall on the Internet Borders tab.
You can select a preset time range from the drop-down menu, or specify a custom window to analyze data across any desired period.
Table 2 Internet border attack event monitoring modules Module
Description
Security Dashboard
Displays the total number of attacks detected by the Intrusion Prevention System (IPS), along with the total count of allowed events, blocked events, and targeted ports within the specified time frame.
Attacks
Plots the total number of times attacks were blocked or allowed by the IPS engine within the specified time frame.
- Data aggregation is subject to minor latency, and the sampling granularity varies based on the selected time range. For details, see Table 1. For real-time data, use Log Query.
- Hovering over any point on the trend chart displays the precise number of blocked and allowed events at that specific timestamp.
- By default, the chart plots both blocked and allowed events. You can show or hide individual metrics by clicking their legends.
Top Statistics
Ranks and summarizes the top 5 attack types, internal source IP addresses, external source IP addresses, target IP addresses, and targeted ports detected or blocked by the IPS engine.
- Click All or Blocked to switch between the chart metrics.
- Click a data point, value, or bar within a specific TOP chart. The system dynamically updates the filters in the Attack Source IP Addresses or Attack Target IP Address tables below.
Attack Source IP Addresses
Lists the top originating source IP addresses with the highest attack frequencies detected or blocked by the IPS engine within the specified time frame.
- The table shows the top 50 records with the highest access traffic. Each record includes the top five ports and applications with the highest access traffic.
- Check whether the traffic is normal or malicious:
- If the IP address is normal, click Add to Whitelist in the Operation column to add it to the whitelist. CFW will directly allow traffic from the IP address.
- If the IP address is malicious, perform any of the following operations:
- Click Add to Blacklist in the Operation column of an IP address. CFW will block the traffic from the IP address.
- Click Add as Blocked Objects above the table. In the slide-out panel, configure the Effective Scope and click OK.
- Click Create Address Group or Add to Address Group to bundle multiple malicious IP addresses. You must then manually configure an access control policy to drop traffic from this group (see Configuring Protection Rules to Block or Allow Internet Border Traffic).
- To export data, select records and click Export above the list, and set the export scope. Data will be exported to the local PC.
Attack Target IP Address
Lists the top targeted destination IP addresses with the highest attack frequencies detected or blocked by the IPS engine within the specified time frame.
- The table shows the top 50 records with the highest access traffic. Each record includes the top five ports and applications with the highest access traffic.
- If the IP address is malicious, click Create Address Group or Add to Address Group to add one or multiple IP addresses to an address group. Then, manually configure the protection rule to block malicious attacks. For details, see Configuring Protection Rules to Block or Allow Internet Border Traffic.
- To export data, select records and click Export above the list, and set the export scope. Data will be exported to the local PC.
Viewing Inter-VPC Border Attack Events
- Configure and enable the VPC border protection, and ensure that traffic passes through the VPC. Configure the attack defense function.
For details about how to enable VPC border protection, see Enabling VPC Border Traffic Protection. For details about how to configure attack defense, see Attack Defense.
- Log in to the CFW console.
- Click
in the upper left corner of the management console and select a region or project. - (Optional) Switch to another firewall instance. If there are multiple firewall instances, you can select a desired instance from the drop-down list in the upper left corner of the page.
- In the navigation pane on the left, choose . On the displayed page, click the Inter-VPC Borders tab.
- View attack events detected by the inter-VPC border firewall on the Inter-VPC Borders tab.
You can select a preset time range from the drop-down menu, or specify a custom window to analyze data across any desired period.
Table 3 Inter-VPC border attack monitoring module Module
Description
Security Dashboard
Displays the total number of attacks detected by the Intrusion Prevention System (IPS), along with the total count of allowed events, blocked events, and targeted ports within the specified time frame.
Attacks
Plots the total number of times attacks were blocked or allowed by the IPS engine within the specified time frame.
- Data aggregation is subject to minor latency, and the sampling granularity varies based on the selected time range. For details, see Table 1. For real-time data, use Log Query.
- Hovering over any point on the trend chart displays the precise number of blocked and allowed events at that specific timestamp.
- By default, the chart plots both blocked and allowed events. You can show or hide individual metrics by clicking their legends.
Top Statistics
Collects statistics on the top 5 attack types, attack source IP addresses, attacked ports, and attack target IP addresses.
- Click All or Blocked to switch between the chart metrics.
- Click a data point, value, or bar within a specific TOP chart. The system dynamically updates the filters in the Attack Source IP Addresses or Attack Target IP Address tables below.
Attack Source IP Addresses
Lists the top originating source IP addresses with the highest attack frequencies detected or blocked by the IPS engine within the specified time frame.
- The table shows the top 50 records with the highest access traffic. Each record includes the top five ports and applications with the highest access traffic.
- If the IP address is malicious, click Create Address Group or Add to Address Group to add one or multiple IP addresses to an address group. Then, manually configure the protection rule to block malicious attacks. For details, see Configuring Protection Rules to Block or Allow VPC Border Traffic.
- To export data, select records and click Export above the list, and set the export scope. Data will be exported to the local PC.
Attack Target IP Address
Lists the top targeted destination IP addresses with the highest attack frequencies detected or blocked by the IPS engine within the specified time frame.
- The table shows the top 50 records with the highest access traffic. Each record includes the top five ports and applications with the highest access traffic.
- If the IP address is malicious, click Create Address Group or Add to Address Group to add one or multiple IP addresses to an address group. Then, manually configure the protection rule to block malicious attacks. For details, see Configuring Internet Border Protection Rules.
- To export data, select records and click Export above the list, and set the export scope. Data will be exported to the local PC.
References
- For details about logs, see Viewing Attack Event Logs.
- For details about attack defense capabilities, see Attack Defense Overview.
- For details about how to handle incorrect IPS blocking, see What Do I Do If IPS Blocks Normal Services?
- For details about how to modify the IPS action, see Configuring Basic IPS Protection. For details about how to modify the virus defense action, see Configuring Virus Defense.
What is your overall rating for this page?
Thank you very much for your feedback. We will continue working to improve the documentation.See the reply and handling status in My Cloud VOC.
For any further questions, feel free to contact us through the chatbot.
Chatbot