Description of Security Monitoring CLA connection log
    • PDF

    Description of Security Monitoring CLA connection log

    • PDF

    Article Summary

    Available in VPC

    Security Monitoring log list collected in Cloud Log Analysis

    IDS

    Name of CLA columnTypeMeaning
    rule_nameStringDetection event name
    severityStringSeverity of risk
    @timestampStringDetection time
    protocolStringProtocol
    source_ipStringSource IP
    source_portIntegerSource Port
    source_ip_countryStringSource country information
    destination_ipStringDestination IP
    destination_portIntegerDestination Port
    destination_ip_countryStringDestination country information
    directionStringNetwork traffic direction
    detect_typeStringType of attack
    region_nameStringRegion name
    productStringProduct code
    platformStringPlatform
    zoneStringZone name
    vpcStringVPC name
    subnetStringSubnet name
    lb_nameStringLoad Balancer name
    lb_instance_noIntegerLoad Balancer number
    lb_domain_nameStringAccess information of Load Balancer
    server_nameStringServer name
    server_instance_noIntegerServer number

    WAF

    Name of CLA columnTypeMeaning
    @timestampStringDetection time
    actionStringAction status
    -Detection: detect
    -Blocking: block
    -Cloaking: cloaking
    destination_ipStringDestination IP
    destination_portIntegerDestination port
    detect_basisStringGrounds for detection
    detect_typeStringDetection type
    domainStringService domain
    lb_nameStringLoad Balancer name
    lb_instance_noIntegerLoad Balancer number
    lb_domain_nameStringAccess information of Load Balancer
    platformStringPlatform
    productStringProduct code
    protocolStringProtocol
    region_nameStringRegion name
    rule_nameStringDetection event
    severityStringSeverity of risk
    server_nameStringServer name
    server_instance_noIntegerServer number
    source_ipStringSource IP
    source_ip_countryStringSource country information
    source_portIntegerSource port
    subnetStringSubnet name
    urlStringPath
    vpcStringVPC name
    xff_ipStringSource IP (X-Forwarded-For IP)
    xff_ip_countryStringSource country information (X-Forwarded-For)
    zoneStringZone name

    IPS

    Name of CLA columnTypeMeaning
    @timestampStringDetection time
    actionStringAction status
    Reset: block, IDS:Reset:detection
    agent_versionStringAgent version
    countIntegerNumber of detections
    destination_ipStringDestination IP
    destination_portIntegerDestination port
    hostStringDetection server IP
    platformStringPlatform
    productStringProduct code
    protocolStringProtocol
    region_nameStringRegion name
    rule_idLongDetection event ID
    rule_nameStringDetection event
    server_nameStringServer name
    server_instance_noIntegerServer number
    severityStringSeverity of risk
    source_ipStringSource IP
    source_portIntegerSource port
    subnetStringSubnet name
    vpcStringVPC name
    xff_ipStringSource IP (X-Forwarded-For IP)
    zoneStringZone name

    Anti-DDoS

    Name of CLA columnTypeMeaning
    @timestampStringDetection time
    actionStringAction status
    - Auto defense start: automatic defense against DDoS attacks has been started.
    - Auto defense end: automatic defense against DDoS attacks has been finished.
    - Detection: detect
    attack_rateIntegerAttack traffic
    destination_ipStringDestination IP
    destination_portIntegerDestination Port
    lb_nameStringLoad Balancer name
    lb_instance_noIntegerLoad Balancer number
    lb_domain_nameStringAccess information of Load Balancer
    platformStringPlatform
    productStringProduct code
    protocolStringProtocol
    region_nameStringRegion name
    rule_nameStringDetection event name
    server_nameStringServer name
    server_instance_noIntegerServer number
    slice_secondsIntegerDetection standard time
    source_ipStringSource IP
    source_portStringSource Port
    subnetStringSubnet name
    threshold_packetsIntegerDetection standard packet
    threshold_bytesIntegerDetection standard bytes
    vpcStringVPC name
    zoneStringZone name
    Note
    • Currently, Anti-DDoS logs available through Cloud Log Analytics include attack detection logs and auto defense start/end logs. Attack blocking logs will be provided later.

    Anti-Virus

    Name of CLA columnTypeMeaning
    @timestampStringDetection time
    actionStringAction status
    agent_versionStringAgent version
    file_pathStringDetection path
    hostStringDetection server IP
    platformStringPlatform
    productStringProduct code
    region_nameStringRegion name
    rule_idLongDetection event ID
    rule_nameStringDetection event
    scan_typeStringScan type
    server_nameStringServer name
    server_instance_noIntegerServer number
    vpcStringVPC name
    subnetStringSubnet name
    zoneStringZone name

    Was this article helpful?

    Changing your password will log you out immediately. Use the new password to log back in.
    First name must have atleast 2 characters. Numbers and special characters are not allowed.
    Last name must have atleast 1 characters. Numbers and special characters are not allowed.
    Enter a valid email
    Enter a valid password
    Your profile has been successfully updated.