Updated on 2026-07-06 GMT+08:00

Enabling Logging

After you authorize CNAD to access Log Tank Service (LTS), you can use the Anti-DDoS logs recorded by LTS for quick and efficient real-time analysis, device O&M management, and analysis of service trends.

Prerequisites

LTS has been enabled. For details, see Managing Log Groups and Managing Log Streams.

You will be billed for using the Log Tank Service (LTS). For billing details, see LTS Pricing Details.

Enabling LTS

  1. Log in to the AAD console.
  2. In the navigation pane on the left, choose Cloud Native Anti-DDoS Advanced > Dashboard. The Data Reports page is displayed.
  3. Click the Logs tab page. Click Connect to LTS.
  4. Select a log group and log stream. For details, see Figure 1.

    Figure 1 Configuring logs
    Table 1 Log parameters

    Parameter

    Description

    Log Group Region

    Select the region to which the log group belongs.

    Log Group

    A log group is the basic unit for LTS to manage logs. It comprises log streams and categorizes them. A log group does not store any log data. It only helps with log stream management.

    Select a log group or click Create Log Group to go to the LTS console and create a log group.

    Attack Log

    A log stream is the basic unit for reading and writing logs. Different types of collected logs are classified and stored in different log streams for easier management.

    Select a log stream or click Create Log Stream to go to the LTS console and create a log stream.

  5. Click OK.
  6. Check or analyze logs.

    After CNAD is connected to LTS, the recorded logs are automatically displayed on the Logs tab page. You can check and analyze the logs. For more information, see Searching for and Analyzing Logs.

    Figure 2 Checking logs

Log Fields in LTS

This section describes the fields of CNAD logs.

Table 2 Key fields

Field

Description

currentConn

Current Connections

maxInPps

Peak rate of incoming packets, in pps.

newConn

New connections

deviceType

Type of the device that reports logs. The default value is CLEAN, indicating the scrubbing device.

attackTypes

Attack type. For details, see Table 3.

zoneIP

Protected IP address.

logType

Log type. The default value is ip_attack_sum, indicating attack logs.

maxDropPps

Peak rate of attack packets, in pps.

maxInKbps

Peak inbound traffic, in kbit/s.

startTime

Time when the attack starts

endTime

End time of the attack. If this parameter is left blank, the attack has not ended yet.

maxDropKbps

Peak attack traffic, in kbps.

attackStatus

Attack status.

  • ATTACK: being attacked
  • NORMAL: normal
Table 3 Attack type description

Value

Attack Type

0-9

User-defined attack type

10

SYN flood attack

11

Ack flood attack

12

SynAck flood attack

13

Fin/Rst flood attack

14

Concurrent connections exceed the threshold.

15

New connections exceed the threshold.

16

TCP fragment attack

17

TCP fragment bandwidth limit attack

18

TCP bandwidth limit attack

19

UDP flood attack

20

UDP fragment attack

21

UDP fragment bandwidth limit attack

22

UDP bandwidth limit attack

23

ICMP bandwidth limit attack

24

Other bandwidth limit attack

25

Traffic limiting attack

26

HTTPS flood attack

27

HTTP flood attack

28

Reserved

29

DNS query flood attack

30

DNS reply flood attack

31

SIP flood attack

32

Blacklist dropping

33

Abnormal HTTP URL behavior

34

TCP fragment abnormal dropping traffic attack

35

TCP abnormal dropping traffic attack

36

UDP fragment abnormal dropping traffic attack

37

UDP abnormal dropping traffic attack

38

ICMP abnormal attack

39

Other abnormal attacks

40

Connection flood attack

41

Domain name hijacking attack

42

DNS poisoning packet attack

43

DNS reflection attack

44

Oversize DNS packet attack

45

Abnormal rate of DNS source requests

46

Abnormal rate of DNS source replies

47

Abnormal rate of DNS domain name requests

48

Abnormal rate of DNS domain name replies

49

DNS request packet TTL anomaly

50

DNS packet format anomaly

51

DNS cache matching and dropping attack

52

Port scan attacks

53

Abnormal TCP packet flag bit

54

BGP attack

55

UDP association defense anomaly

56

DNS NO such Name

57

Other fingerprint attacks

58

Zone traffic limit attack

59

HTTP slow attacks

60

Malware prevention

61

Domain name blocking

62

Filtering

63

Web attack packet capture

64

SIP source rate limiting