> For the complete documentation index, see [llms.txt](https://docs.link11.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.link11.com/product-guides/network-ddos-v3/interface/attack-reports.md).

# Attack Reports

<figure><img src="/files/6G2sB9RruYwA04gmd9FF" alt=""><figcaption></figcaption></figure>

The Attack Events page lists all periods of active mitigation recorded for the customer. Each entry represents a distinct attack event — a period when the system detected a high quality signal and activated one or more mitigation strategies in response.

An Attack ID is assigned when mitigation begins (e.g., `ATK-2026-0043`). This ID is used throughout the interface and in the Explorer to link all related events.

### Table Columns

| Column       | Description                                                                                                                                       |
| ------------ | ------------------------------------------------------------------------------------------------------------------------------------------------- |
| Status       | **Active** or **Ended**.                                                                                                                          |
| Attack ID    | Unique ID for this Attack Event                                                                                                                   |
| Protected IP | The protected IP address that was targeted.                                                                                                       |
| Description  | Summary Description of the Attack Type/Vector and Magnitude                                                                                       |
| Start Time   | Date and time when the attack event began — i.e., when the first mitigation was activated.                                                        |
| Duration     | Length of Attack                                                                                                                                  |
| Severity     | Internal scoring metric used to class attacks. Uses the magnitude, intensity, duration and general effectiveness of the attack to provide a score |

***

## Attack Report

The Attack Report provides a detailed record of a single attack event. It is accessed by clicking on any row in the Attack Events page.

### Report Header

| Field                  | Description                                                          |
| ---------------------- | -------------------------------------------------------------------- |
| **Attack ID**          | The unique identifier for this attack event (e.g., `ATK-2026-0043`). |
| **Status**             | Active (mitigations running) or Ended (attack concluded).            |
| **Max Rate**           | The peak traffic rate in Gbps observed during the attack.            |
| **Max Rate (packets)** | The peak packet rate in Mpps.                                        |
| **Sources**            | The number of unique source IPs involved.                            |
| **% Blocked**          | The proportion of attack traffic that was successfully blocked.      |

### Key Stats Panel

| Field              | Description                                                                           |
| ------------------ | ------------------------------------------------------------------------------------- |
| **Protected IP**   | The destination IP that was under attack.                                             |
| **Primary Vector** | The primary attack type detected (e.g., UDP Flood, TCP SYN Flood, NTP Amplification). |
| **Start / End**    | Timestamps for when the attack began and when mitigations ended.                      |
| **Duration**       | Total length of the attack event.                                                     |
| **State**          | Active or Ended.                                                                      |

<figure><img src="/files/R00WaqZ2H68cGk6iBFP5" alt=""><figcaption></figcaption></figure>

### Mitigation Activity

This section shows all mitigation strategies activated during the attack. Each strategy is displayed as a labelled pill (e.g., UDP Flood, NTP Amplification, DNS Amplification). The chart shows packets dropped per mitigation strategy over the attack timeline, allowing administrators to see which mitigations were most active and when.

A summary line shows the total number of mitigation strategies activated and the total duration of mitigation activity.

### Dashboard Tabs

| Tab             | Content                                                                                                               |
| --------------- | --------------------------------------------------------------------------------------------------------------------- |
| **Overview**    | High-level traffic overview with inbound, blocked, and outbound traffic. Top protocols and attack sources by country. |
| **Traffic**     | Full attack traffic timeline showing inbound, blocked, and outbound volumes across the attack duration.               |
| **Protocols**   | Protocol distribution throughout the attack.                                                                          |
| **Sources**     | Detailed breakdown of attack source IPs, ASNs, and countries.                                                         |
| **Mitigations** | Per-mitigation statistics — total blocked bytes and packets for each strategy activated.                              |

<figure><img src="/files/4uBN6ubendX4XUIixDIv" alt=""><figcaption></figcaption></figure>

### Events Timeline

The bottom of the Attack Report contains a filterable timeline of every event recorded during the attack. This is the same Explorer view scoped to this Attack ID. Events include:

* Attack Detected
* Mitigation Activated / Deactivated
* Mitigation Status Update
* Cooldown Period Started / Completed
* Cooldown Canceled — Attack Resumed
* Attack Source Blocked

Filters can be added to narrow the timeline by event type, source IP, destination IP, or other fields.

<figure><img src="/files/7W8ifGyltKTUMDN7ea1b" alt=""><figcaption></figcaption></figure>

### Export

* **PDF** — a formatted report suitable for sharing with stakeholders or archiving.
* **CSV** — raw event and traffic data for further analysis.

A shareable link to the report can also be generated for sharing with other portal users.
