> For the complete documentation index, see [llms.txt](https://docs.link11.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.link11.com/product-guides/network-ddos-v3/interface/explorer.md).

# Explorer

The Explorer is a searchable, filterable log of every event recorded by the Network DDoS platform. It provides a complete audit trail across all attacks and mitigations, and is the primary tool for investigating specific traffic events.

### Table Columns

| Column          | Description                                                                            |
| --------------- | -------------------------------------------------------------------------------------- |
| Event Timestamp | Date and time the event was recorded.                                                  |
| Destination     | The protected IP address the event relates to.                                         |
| Event           | The event type (e.g., Attack Detected, Mitigation Activated, Cooldown Period Started). |

### Event Types

| Event Type                                     | Description                                                                                  |
| ---------------------------------------------- | -------------------------------------------------------------------------------------------- |
| **Attack Detected**                            | A high quality signal was confirmed and an attack event was opened.                          |
| **Mitigation Activated**                       | A specific mitigation strategy was enabled.                                                  |
| **Mitigation Monitoring**                      | A mitigation strategy is observing traffic without actively blocking (monitoring-only mode). |
| **Mitigation Status Update**                   | A periodic update on the effectiveness of an active mitigation.                              |
| **Mitigation Deactivated**                     | A mitigation strategy was disabled.                                                          |
| **Cooldown Period Started**                    | Mitigations are winding down. The system is monitoring to ensure the attack does not resume. |
| **Cooldown Completed**                         | The cooldown period ended without renewed activity. The system has returned to peacetime.    |
| **Cooldown Canceled — Attack Resumed**         | Renewed attack activity was detected during cooldown. Mitigations were re-engaged.           |
| **Attack Source Blocked**                      | A specific source IP was blocked.                                                            |
| **High Packet Rate / High Bandwidth Detected** | Individual traffic anomaly signals.                                                          |
| **Fragment Reassembly Failed / Succeeded**     | Packet fragmentation events.                                                                 |
| **Protected IP Added / Removed**               | A protected IP was added to or removed from active monitoring.                               |

### Expanding Rows

Clicking the arrow on any row expands it to show the full detail fields for that event. Fields vary by event type — examples include Attack Type, Attack Rate, Bandwidth, Attack Sources, Primary Source, Protected IP, Attack ID, and Detection Time.

Individual field values can be clicked to add them as active filters.

### Filtering

Click **Add Filter** to add a filter condition. Multiple filters can be combined. Active filters appear as chips above the table and can be removed individually. Fields available for filtering include: Source IP, Destination IP, Event Type, Attack UID, and others.

An existing filter can be updated by applying a new filter on the same field with a different value.

Example:

Severity is Low can be updated by applying a Severity is Medium filter. This will overwrite the existing filter.

### Time Range

The Explorer uses the same date picker found in the top right.
