> For the complete documentation index, see [llms.txt](https://docs.link11.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.link11.com/product-guides/web-ddos/interface/dashboard.md).

# Dashboard

The Dashboard displays a wide variety of analytics for the chosen instance(s) and date/time ranges.

## Requests <a href="#id-webddos-dashboard-requests" id="id-webddos-dashboard-requests"></a>

<figure><img src="/files/r7U4wG60H4E1Kw3Ovcvt" alt=""><figcaption></figcaption></figure>

### **Max Hits**

Refers to the highest rate of traffic observed at the given time interval. This number displays the highest traffic spike across all selected instances.

### **Hits**

Hits provides the traffic rate over the time interval. This number is the aggregate of all selected instances.

***

## Bandwidth <a href="#id-webddos-dashboard-bandwidth" id="id-webddos-dashboard-bandwidth"></a>

<figure><img src="/files/rRZKSgTPJu7W5ikpLy2i" alt=""><figcaption></figcaption></figure>

### **Total Cluster Traffic**

Total data transferred across the Link11 network, both inbound and outbound, for the selected instance(s).

### **Max Cleanpipe**

Clean traffic is defined as the accumulated traffic (in gigabytes) transported in and out each month that are routed over the Link11 network to the customer origin.

The value details the amount of traffic transiting our network, destined for the customer origin, that was not blocked by Link11. All blocked requests are excluded from the clean traffic value.&#x20;

Max Cleanpipe is a static value that shows how much bandwidth the customer has committed to in their contract. When traffic exceeds this, it is billed at a rate specified in the contract.

### **Client Cluster Traffic**

Refers to network traffic between the client and the Link11 proxy server, both inbound and outbound

{% hint style="info" %}
**Note:**

Client Cluster Traffic can include *both* **legitimate** requests from customers as well as **malicious** traffic from attackers
{% endhint %}

### **Origin Cluster Traffic**

Refers to network traffic between the customer origin and the Link11 proxy server, both inbound and outbound.

***

## Unique IPs <a href="#id-webddos-dashboard-uniqueips" id="id-webddos-dashboard-uniqueips"></a>

<figure><img src="/files/p4hLlKSN2hzS3ugfLDKR" alt=""><figcaption></figcaption></figure>

### **Unique Visitors**

This metric measures the number of **distinct users** that are accessing a website or service protected by the DDoS proxy. It can be based on different parameters like the user's cookies, the user agent, etc.,  and it can help admins to understand how many different individuals are using the service.

### **Unique IPs**

Unique IP is a metric that measures the number of **distinct IP addresses** that are sending requests to the website or service. This can provide insight into the number of different devices or networks that are accessing the service.

{% hint style="info" %}
**Note:**

Both metrics are important when assessing the performance of a DDoS protection proxy, as they can provide insight into the size and scale of the traffic, and also help to identify patterns of use and detect anomalies.

For example, if the number of unique visitors is **high** but the number of unique IPs is **low**, it may indicate that a relatively small number of users are accessing the service from a large number of different devices or networks.
{% endhint %}

***

## Threats <a href="#id-webddos-dashboard-threats" id="id-webddos-dashboard-threats"></a>

<figure><img src="/files/qGcrEjePA6PezCfNWMfV" alt=""><figcaption></figcaption></figure>

| **Name**            | **Meaning**                                                                                                                                                                                                                                  | **Default Value**                                                                                                                                          |
| ------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------- |
| DDoS Attack         | <p>Detected DDoS attack</p><p><br>Clicking on the DDoS Attack marker in the graph will redirect you to <a href="https://link11.atlassian.net/wiki/spaces/CD/pages/2293923908/Web+DDoS+Attacks+Attack+Details">attack details</a>.</p>        | *DDoS Attack Markers scale horizontally to indicate the duration of an attack. The vertical scale of an Attack Marker does **not** indicate its magnitude* |
| Origin Error        | <p>Can be manifested in 2 different errors:<br></p><p>Origin Connect Error: TCP Connection could not be established<br><br>Server Error: TCP Connection was established but suddenly closed (for example: Server restarts, or a timeout)</p> |                                                                                                                                                            |
| Origin Slow Connect | A connection to the origin IP Address is not established within *N* seconds                                                                                                                                                                  | <p>10 seconds</p><p><em>maximal wait time is 30 seconds</em></p>                                                                                           |
| WAF Blocks          | Count of requests blocked by WAF on the instance                                                                                                                                                                                             | *values count towards total number of Threats*                                                                                                             |

***

## Origin Monitoring <a href="#id-webddos-dashboard-originmonitoring" id="id-webddos-dashboard-originmonitoring"></a>

<figure><img src="/files/22btTG4rdHtpoUut8ai3" alt=""><figcaption></figcaption></figure>

### **Origin Availability**

Refers to the ability of a customer origin server to respond to requests from clients. It is a measure of the availability of the service provided by the origin server, and it indicates whether the service is up and running or not.

This availability is measured in percent.

***

## HTTP Response <a href="#id-webddos-dashboard-httpresponse" id="id-webddos-dashboard-httpresponse"></a>

<figure><img src="/files/av1c7jJBeHPaN25sSvC3" alt=""><figcaption></figcaption></figure>

### **OK (200)**

The request was successful

### **Not Modified (304)**

The client used a cached copy because the requested page has not been modified.

### **Redirect (302 or 301)**

Page moved permanently (301) or temporarily (302)

### **Bad Request (400)**

Server detected a syntax error

### **Not Found (404)**

Page does not exist on the server

### **Server Error (5xx)**

Server-side error detected

***

## Performance <a href="#id-webddos-dashboard-performance" id="id-webddos-dashboard-performance"></a>

<figure><img src="/files/ydAYZXcshjaOpwIJj37u" alt=""><figcaption></figcaption></figure>

### **Origin Response Time**

Displays the average origin response time during the time interval. The Origin Response Time is calculated from the time a request is initiated from the Link11 Web DDoS Proxy to the time the Customer Origin completes its response.

***

### **Number of Threats**

Displays the aggregate number of WAF blocks and DDoS attacks in a chosen time frame. Detailed view can be found in [Threats](#id-webddos-dashboard-threats).

<figure><img src="/files/2CcquQnVZwkyFGqpK8ne" alt=""><figcaption></figcaption></figure>

### **Usage per Selected Time**

Summarizes traffic usage for a give time frame. Details can be found in [Bandwidth](#id-webddos-dashboard-bandwidth).

<figure><img src="/files/FA0T1KBPV9mF2w9MNpw2" alt=""><figcaption></figcaption></figure>

{% hint style="info" %}
The Total Bytes is the amount of consumed Cleantraffic. Your Cleantraffic commitment is listed in your contract under product details. Any traffic exceeding your Cleantraffic commitment will be charged according to your contract as additional clean traffic.
{% endhint %}

### **Last 50 Blocked IPs**

Displays the last 50 blocked IPs with information on Attacker IP, Attacker ISP, Country attack was started in, and Status of the Attacker IP.

<figure><img src="/files/GosG3nfq4znzDBsyZWf4" alt=""><figcaption></figcaption></figure>

### **Show Blocklist**

Clicking on the show Blocklist button will redirect you to the [Blocklist](/product-guides/web-ddos/interface/blocklist.md).

<figure><img src="/files/lhHV8chKzmJOrBRlfmGi" alt=""><figcaption></figcaption></figure>
