Updated on 2026-07-06 GMT+08:00

Configuring Metric Monitoring Alarms

DDoS attacks are growing in frequency, volume, and sophistication, posing a constant threat to instances and IP assets. Traditional monitoring often fails to distinguish malicious bursts from normal service peaks. Policy optimization often relies on expert experience rather than data-driven analysis.

In Cloud Eye, you can configure metric monitoring rules for AAD instances or protected EIPs. You can receive accurate, timely alarms on attacks and maintain real-time visibility into your protection status. This transparency eliminates "black box" defenses, ensuring all policy optimizations are based on statistics rather than personal judgement.

If you need to customize more metrics, you can report them to Cloud Eye through API requests. For details, see Adding Monitoring Data.

Background Information

Cloud Eye provides multi-dimensional monitoring for resources such as ECSs and bandwidth. For more information, see What Is Cloud Eye?

Billing

Alarm notifications sent by SMN will be billed based on their frequency and message length. For details, see Product Pricing Details.

Setting Monitoring Alarm Rules in Batches

  1. Log in to the Cloud Eye console.
  2. In the navigation pane on the left, choose Alarm Management > Alarm Rules.
  3. In the upper right corner of the page, click Create Alarm Rule.
  4. Enter the alarm rule information, as shown in Configuring AAD alarm rules. For details about how to enter the alarm rule information, see Table 1.

    Figure 1 Configuring AAD alarm rules
    Table 1 AAD alarm rule parameters

    Parameter

    Description

    Name

    The system generates a random name and you can modify it.

    Description

    Description about the rule.

    Alarm Type

    By default, Metric is selected. For details about how to configure event alarms, see Setting Event Alarm Notifications.

    Cloud Service

    For AAD, select DDoS - Instance ID from the drop-down list box.

    Resource Level

    Select the resource dimension to be monitored.

    • Cloud product: Both instance and IP monitoring are supported.
    • Specific dimension: Select an instance or a protected IP address as the monitored object.
      • Instance ID: An instance is monitored.
      • Instance ID - IP: A protected IP address is monitored.

    Monitoring Scope

    Monitoring scope the alarm rule applies to.

    • All resources: An alarm will be triggered anytime an instance, including resources that will be purchased, in this dimension meets the alarm rule.
    • Specific resources: Click Select Specific Resources and select the resources to be monitored.

    Method

    • Associate template: If you associate with a template, any modification made to the template will also be synchronized to the policies of the alarm rule associated with the template. For details about how to create a template, see Creating a Custom Template.
    • Configure manually: You can set a custom rule for monitored objects.

    Template

    If Method is set to Associate template, this parameter is mandatory.

    You can select a default alarm template or create a custom template.

    Alarm Policy

    If Method is set to Configure manually, this parameter is mandatory.

    You can add up to 50 alarm policies to an alarm rule.

    • any policy: An alarm is reported when any of the alarm policies is met.
    • all policies: An alarm is reported only when all the alarm policies are met.

    Alarm Notification

    Whether to notify users when alarms are triggered. Notifications can be sent by email, text message, or HTTP/HTTPS message.

    Notification Recipient

    Select an option as needed.

    • Notification policies: You can set up different notification scopes in a notification policy to alert specific owners by alarm severity or at a specified schedule. For details about how to create a notification policy, see Creating a Notification Policy.
    • Contact groups: To send alarm notifications to a fixed group of recipients, create a notification group and add the recipients to it. For details, see Creating a Recipient and Notification Group.
    • Topic subscriptions: Choose this if the current region does not support alarm notifications or the recipients have been configured in SMN. You can select a cloud account contact or a topic created in SMN.

  5. Click Create. If a success message is displayed, the alarm rule has been created.

Setting Monitoring Alarm Rules for a Specified Resource

  1. Log in to the Cloud Eye console.
  2. In the navigation pane on the left, choose Cloud Service Monitoring and click DDoS DDOS.

    Figure 2 Selecting a service

  3. On the Details page, choose DDoS > Instance ID.
  4. In the row of an object, click More > Create Alarm Rule.
  5. Enter the alarm rule information, as shown in Configuring AAD alarm rules. For details about how to enter the alarm rule information, see Table 2.

    Figure 3 Configuring AAD alarm rules
    Table 2 AAD alarm rule parameters

    Parameter

    Description

    Name

    Name of an alarm rule. The system randomly generates a name and you can modify it.

    Description

    Description about the rule.

    Alarm Type

    By default, Metric is selected. For details, see Setting Event Alarm Notifications.

    Cloud Service

    For AAD, select DDoS - Instance ID from the drop-down list box.

    Resource Level

    Select the resource dimension to be monitored.

    • Cloud product: Both instance and IP monitoring are supported.
    • Specific dimension: Select an instance or a protected IP address as the monitored object.
      • Instance ID: An instance is monitored.
      • Instance ID - IP: A protected IP address is monitored.

    Monitoring Scope

    Monitoring scope the alarm rule applies to.

    • All resources: An alarm will be triggered anytime an instance, including resources that will be purchased, in this dimension meets the alarm rule.
    • Specific resources: Click Select Specific Resources and select the resources to be monitored.

    Instance

    Click Reselect to add multiple objects to be monitored.

    Method

    • Associate template: If you associate with a template, any modification made to the template will also be synchronized to the policies of the alarm rule associated with the template. For details about how to create a template, see Creating a Custom Template.
    • Configure manually: You can set a custom rule for monitored objects.

    Template

    If Method is set to Associate template, this parameter is mandatory.

    You can select a default alarm template or create a custom template.

    Alarm Policy

    If Method is set to Configure manually, this parameter is mandatory.

    You can add up to 50 alarm policies to an alarm rule.

    • any policy: An alarm is reported when any of the alarm policies is met.
    • all policies: An alarm is reported only when all the alarm policies are met.

    Alarm Notification

    Whether to notify users when alarms are triggered. Notifications can be sent by email, text message, or HTTP/HTTPS message.

    Notification Recipient

    Select an option as needed.

    • Notification policies: You can set up different notification scopes in a notification policy to alert specific owners by alarm severity or at a specified schedule. For details about how to create a notification policy, see Creating a Notification Policy.
    • Contact groups: To send alarm notifications to a fixed group of recipients, create a notification group and add the recipients to it. For details, see Creating a Recipient and Notification Group.
    • Topic subscriptions: Choose this if the current region does not support alarm notifications or the recipients have been configured in SMN. You can select a cloud account contact or a topic created in SMN.

  6. Click Create. If a success message is displayed, the alarm rule has been created.

Related Operations

Adjusting a policy: For details, see Configuring a Protection Policy.