Enabling DDoS Alarm Notifications
DDoS attacks typically peak instantaneously, triggering service outages within minutes. Many users only notice the attacks after their services have been severely affected, missing the optimal time for response.
Cloud Eye enables event monitoring for protected EIPs and generates alarms for scrubbing, blocking, and unblocking events. You can receive accurate, timely alarms on attacks and maintain real-time visibility into your protection status.
After the event alarm notification function is enabled, you can view event details on the Event Monitoring page of the Cloud Eye console when an event occurs.
Background Information
Cloud Eye provides multi-dimensional monitoring for resources such as ECSs and bandwidth. For more information, see What Is Cloud Eye?
Billing
Alarm notifications sent by SMN will be billed based on their frequency and message length. For details, see Product Pricing Details.
Enabling Event Alarm Notifications
- Log in to the Cloud Eye console.
- In the navigation pane on the left, choose Event Monitoring.
- In the upper right corner of the page, click Create Alarm Rule.
- Set alarm parameters by referring to Table 1. Figure 1 Alarm parameters
Table 1 Parameter description Parameter
Description
Name
Name of an alarm rule. The system randomly generates a name and you can modify it.
Description
Description about the rule.
Alarm Type
By default, Event is selected. For details about how to configure metric monitoring for EIPs, see Creating an Alarm Rule and Notifications.
Event Type
Options include System event and Custom event. Select System event.
Event Source
Service the event is generated for. Choose Elastic IP.
Monitoring Scope
Monitoring scope the alarm rule applies to.
- All resources: An alarm will be triggered anytime a resource, including resources that will be purchased, in this dimension meets the alarm rule.
- Specific resources: Click Select Specific Resources and select the resources to be monitored.
Method
- Associate template: If you associate with a template, any modification made to the template will also be synchronized to the policies of the alarm rule associated with the template. For details about how to create a template, see Creating a Custom Template.
- Configure manually: You can set a custom rule for monitored objects.
Alarm Policy
You are advised to select EIP blocked, EIP unblocked, Start Anti-DDoS traffic scrubbing, and Stop Anti-DDoS traffic scrubbing.
When the traffic is greater than 10,000 kbit/s, the system sends an alarm notification when scrubbing starts and when scrubbing ends. When the traffic is less than 10,000 kbit/s, no alarm notification is sent.
Notification Recipient
Select an option as needed.
- Notification policies: You can set up different notification scopes in a notification policy to alert specific owners by alarm severity or at a specified schedule. For details about how to create a notification policy, see Creating a Notification Policy.
- Contact groups: To send alarm notifications to a fixed group of recipients, create a notification group and add the recipients to it. For details, see Creating a Recipient and Notification Group.
- Topic subscriptions: Choose this if the current region does not support alarm notifications or the recipients have been configured in SMN. You can select a cloud account contact or a topic created in SMN.
- Click Create. If a success message is displayed, the alarm rule has been created.
Related Operations
- Removing a blackhole: If a blackhole event occurs, handle it by referring to Huawei Cloud Blackhole Policy.
- Adjusting the policy: If a scrubbing event occurs, you may need to adjust the traffic scrubbing policy. For details, see Setting a Traffic Scrubbing Threshold to Block Attack Traffic.
Feedback
Was this page helpful?
Provide feedbackThank you very much for your feedback. We will continue working to improve the documentation.See the reply and handling status in My Cloud VOC.
For any further questions, feel free to contact us through the chatbot.
Chatbot