Updated on 2026-09-14 GMT+08:00

Event Center

Scenario

During routine network security O&M, enterprises must continuously monitor the security status of their network traffic. CFW features an Event Center that provides a consolidated dashboard of protection statistics compiled over the past 7 days. This dashboard tracks inbound and outbound Internet traffic and VPC border traffic that has been inspected by your attack defense engines (including IPS, Reverse Shell, Sensitive Directory Scanning, and Antivirus). This visibility helps you monitor traffic security posture in real time and rapidly fine-tune your protection configurations.

This section describes how to use the Event Center to view and analyze attack defense metrics.

Notes and Constraints

  • Intrusion prevention does not support decryption detection and defense for TLS- and SSL-encrypted traffic.
  • There is a delay in collecting statistics in the Attacks module. The value varies according to the query time range. For details, see Table 1. If you need to query real-time data, you are advised to use Log Query.
    Table 1 Attack trend time range parameters

    Time Range

    Calculation Logic

    Last 1 hour

    Take the average value from the preceding 1-minute interval, rounded to the nearest minute. For example, if a query is run at 08:45:59, data is collected from 07:45:00 to 08:45:00.

    Last 24 hours

    Take the average value of the preceding 5-minute interval, rounded down to the nearest multiple of 5 minutes. For example, if a query is run at 2026/06/30 08:48:59, data is collected from 2026/06/29 08:45:00 to 2026/06/30 08:45:00.

    Last 7 days

    Take the average value of the preceding 1-hour interval, rounded to the nearest hour. For example, if a query is run at 2026/06/30 08:45:59, data is collected from 2026/06/23 08:00:00 to 2026/06/30 08:00:00.

    Custom

    • 5 minutes to 6 hours: Take the 1-minute average value, matching the logic of the Last 1 hour range.
    • 6 hours (inclusive) to 3 days: Take the 5-minute average value, matching the logic of the Last 24 hours range.
    • 3 days (inclusive) to 7 days (inclusive): Take the 30-minute average value, following a similar aggregation method to the Last 7 days range.

Viewing Attack Events

To view attack events, perform the following operations.

Viewing Internet Border Attacks

  1. Enable EIP protection, and ensure that existing traffic passes through the EIP. Configure the attack defense function.

    For details about how to enable EIP protection, see Enabling Internet Border Traffic Protection. For details about how to configure attack defense, see Attack Defense.

  2. Log in to the CFW console.
  3. Click in the upper left corner of the management console and select a region or project.
  4. (Optional) Switch to another firewall instance. If there are multiple firewall instances, you can select a desired instance from the drop-down list in the upper left corner of the page.
  5. In the navigation pane on the left, choose O&M Analysis > Event Center. The Internet Borders tab is displayed by default.
  6. Select a protection border.
  7. View attack events detected by the Internet border firewall on the Internet Borders tab.

    You can select a preset time range from the drop-down menu, or specify a custom window to analyze data across any desired period.

    Table 2 Internet border attack event monitoring modules

    Module

    Description

    Security Dashboard

    Displays the total number of attacks detected by the Intrusion Prevention System (IPS), along with the total count of allowed events, blocked events, and targeted ports within the specified time frame.

    Attacks

    Plots the total number of times attacks were blocked or allowed by the IPS engine within the specified time frame.

    • Data aggregation is subject to minor latency, and the sampling granularity varies based on the selected time range. For details, see Table 1. For real-time data, use Log Query.
    • Hovering over any point on the trend chart displays the precise number of blocked and allowed events at that specific timestamp.
    • By default, the chart plots both blocked and allowed events. You can show or hide individual metrics by clicking their legends.

    Top Statistics

    Ranks and summarizes the top 5 attack types, internal source IP addresses, external source IP addresses, target IP addresses, and targeted ports detected or blocked by the IPS engine.

    • Click All or Blocked to switch between the chart metrics.
    • Click a data point, value, or bar within a specific TOP chart. The system dynamically updates the filters in the Attack Source IP Addresses or Attack Target IP Address tables below.

    Attack Source IP Addresses

    Lists the top originating source IP addresses with the highest attack frequencies detected or blocked by the IPS engine within the specified time frame.

    • The table shows the top 50 records with the highest access traffic. Each record includes the top five ports and applications with the highest access traffic.
    • Check whether the traffic is normal or malicious:
      • If the IP address is normal, click Add to Whitelist in the Operation column to add it to the whitelist. CFW will directly allow traffic from the IP address.
      • If the IP address is malicious, perform any of the following operations:
        • Click Add to Blacklist in the Operation column of an IP address. CFW will block the traffic from the IP address.
        • Click Add as Blocked Objects above the table. In the slide-out panel, configure the Effective Scope and click OK.
        • Click Create Address Group or Add to Address Group to bundle multiple malicious IP addresses. You must then manually configure an access control policy to drop traffic from this group (see Configuring Protection Rules to Block or Allow Internet Border Traffic).
    • To export data, select records and click Export above the list, and set the export scope. Data will be exported to the local PC.

    Attack Target IP Address

    Lists the top targeted destination IP addresses with the highest attack frequencies detected or blocked by the IPS engine within the specified time frame.

    • The table shows the top 50 records with the highest access traffic. Each record includes the top five ports and applications with the highest access traffic.
    • If the IP address is malicious, click Create Address Group or Add to Address Group to add one or multiple IP addresses to an address group. Then, manually configure the protection rule to block malicious attacks. For details, see Configuring Protection Rules to Block or Allow Internet Border Traffic.
    • To export data, select records and click Export above the list, and set the export scope. Data will be exported to the local PC.

Viewing Inter-VPC Border Attack Events

  1. Configure and enable the VPC border protection, and ensure that traffic passes through the VPC. Configure the attack defense function.

    For details about how to enable VPC border protection, see Enabling VPC Border Traffic Protection. For details about how to configure attack defense, see Attack Defense.

  2. Log in to the CFW console.
  3. Click in the upper left corner of the management console and select a region or project.
  4. (Optional) Switch to another firewall instance. If there are multiple firewall instances, you can select a desired instance from the drop-down list in the upper left corner of the page.
  5. In the navigation pane on the left, choose O&M Analysis > Event Center. On the displayed page, click the Inter-VPC Borders tab.
  6. View attack events detected by the inter-VPC border firewall on the Inter-VPC Borders tab.

    You can select a preset time range from the drop-down menu, or specify a custom window to analyze data across any desired period.

    Table 3 Inter-VPC border attack monitoring module

    Module

    Description

    Security Dashboard

    Displays the total number of attacks detected by the Intrusion Prevention System (IPS), along with the total count of allowed events, blocked events, and targeted ports within the specified time frame.

    Attacks

    Plots the total number of times attacks were blocked or allowed by the IPS engine within the specified time frame.

    • Data aggregation is subject to minor latency, and the sampling granularity varies based on the selected time range. For details, see Table 1. For real-time data, use Log Query.
    • Hovering over any point on the trend chart displays the precise number of blocked and allowed events at that specific timestamp.
    • By default, the chart plots both blocked and allowed events. You can show or hide individual metrics by clicking their legends.

    Top Statistics

    Collects statistics on the top 5 attack types, attack source IP addresses, attacked ports, and attack target IP addresses.

    • Click All or Blocked to switch between the chart metrics.
    • Click a data point, value, or bar within a specific TOP chart. The system dynamically updates the filters in the Attack Source IP Addresses or Attack Target IP Address tables below.

    Attack Source IP Addresses

    Lists the top originating source IP addresses with the highest attack frequencies detected or blocked by the IPS engine within the specified time frame.

    • The table shows the top 50 records with the highest access traffic. Each record includes the top five ports and applications with the highest access traffic.
    • If the IP address is malicious, click Create Address Group or Add to Address Group to add one or multiple IP addresses to an address group. Then, manually configure the protection rule to block malicious attacks. For details, see Configuring Protection Rules to Block or Allow VPC Border Traffic.
    • To export data, select records and click Export above the list, and set the export scope. Data will be exported to the local PC.

    Attack Target IP Address

    Lists the top targeted destination IP addresses with the highest attack frequencies detected or blocked by the IPS engine within the specified time frame.

    • The table shows the top 50 records with the highest access traffic. Each record includes the top five ports and applications with the highest access traffic.
    • If the IP address is malicious, click Create Address Group or Add to Address Group to add one or multiple IP addresses to an address group. Then, manually configure the protection rule to block malicious attacks. For details, see Configuring Internet Border Protection Rules.
    • To export data, select records and click Export above the list, and set the export scope. Data will be exported to the local PC.

References