Feature
Filter DDoS attack traffic from Logpush jobs
Logpush jobs can now exclude distributed denial-of-service attack traffic from delivered logs, reducing noise and focusing on legitimate traffic. This feature supports http_requests, firewall_events, and network_analytics_logs datasets via a new filter_attack_traffic flag.
Logpush jobs can now exclude identified distributed denial-of-service (DDoS) attack traffic. This option reduces attack traffic in delivered logs.
It supports the http_requests, firewall_events, and network_analytics_logs datasets.
In the dashboard, select Exclude DDoS attack traffic under Advanced Options. With the API, add this field to a job request:
{
"filter_attack_traffic": true
}
For more information, refer to API configuration.
logpushddoslogssecurityapi
Source: original entry ↗