megachangelog
Feature

Filter DDoS attack traffic from Logpush jobs

Logpush jobs can now exclude distributed denial-of-service attack traffic from delivered logs, reducing noise and focusing on legitimate traffic. This feature supports http_requests, firewall_events, and network_analytics_logs datasets via a new filter_attack_traffic flag.

Logpush jobs can now exclude identified distributed denial-of-service (DDoS) attack traffic. This option reduces attack traffic in delivered logs.

It supports the http_requests, firewall_events, and network_analytics_logs datasets.

In the dashboard, select Exclude DDoS attack traffic under Advanced Options. With the API, add this field to a job request:

{
	"filter_attack_traffic": true
}

For more information, refer to API configuration.

logpushddoslogssecurityapi

Source: original entry ↗