Skip to content

Commit 5c35537

Browse files
authored
Merge pull request #223935 from AbdullahBell/ddos-view-alerts-defender
DDoS Protection: New Article: View DDoS Protection alerts in Microsoft Defender for Cloud
2 parents f2d7b99 + f8af558 commit 5c35537

File tree

3 files changed

+52
-0
lines changed

3 files changed

+52
-0
lines changed

articles/ddos-protection/TOC.yml

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -60,6 +60,10 @@
6060
items:
6161
- name: Configure metric alerts through portal
6262
href: alerts.md
63+
- name: View Monitoring and Logging
64+
items:
65+
- name: View alerts in Microsoft Defender for Cloud
66+
href: ddos-view-alerts-defender-for-cloud.md
6367
- name: Test with simulation partners
6468
href: test-through-simulations.md
6569
- name: Manage permissions and restrictions
Lines changed: 48 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,48 @@
1+
---
2+
title: 'View Azure DDoS Protection alerts in Microsoft Defender for Cloud'
3+
description: Learn how to view DDoS protection alerts in Microsoft Defender for Cloud.
4+
services: ddos-protection
5+
documentationcenter: na
6+
author: AbdullahBell
7+
ms.service: ddos-protection
8+
ms.topic: how-to
9+
ms.tgt_pltfrm: na
10+
ms.workload: infrastructure-services
11+
ms.date: 01/30/2023
12+
ms.author: abell
13+
---
14+
15+
# View Azure DDoS Protection alerts in Microsoft Defender for Cloud
16+
17+
Microsoft Defender for Cloud provides a list of [security alerts](../security-center/security-center-managing-and-responding-alerts.md), with information to help investigate and remediate problems. With this feature, you get a unified view of alerts, including DDoS attack-related alerts and the actions taken to mitigate the attack in near-time.
18+
There are two specific alerts that you'll see for any DDoS attack detection and mitigation:
19+
20+
- **DDoS Attack detected for Public IP**: This alert is generated when the DDoS protection service detects that one of your public IP addresses is the target of a DDoS attack.
21+
- **DDoS Attack mitigated for Public IP**: This alert is generated when an attack on the public IP address has been mitigated.
22+
To view the alerts, open **Defender for Cloud** in the Azure portal and select **Security alerts**. Under **Threat Protection**, select **Security alerts**. The following screenshot shows an example of the DDoS attack alerts.
23+
24+
:::image type="content" source="./media/manage-ddos-protection/ddos-alert-asc.png" alt-text="Screenshot of DDoS Alert in Microsoft Defender for Cloud." lightbox="./media/manage-ddos-protection/ddos-alert-asc.png":::
25+
26+
## Prerequisites
27+
28+
- An Azure account with an active subscription. [Create an account for free](https://azure.microsoft.com/free/?WT.mc_id=A261C142F).
29+
- [DDoS Network Protection](manage-ddos-protection.md) must be enabled on a virtual network or [DDoS IP Protection (Preview)](manage-ddos-protection-powershell-ip.md) must be enabled on a public IP address.
30+
31+
## View alerts in Microsoft Defender for Cloud
32+
33+
1. Sign in to the [Azure portal](https://portal.azure.com/).
34+
1. In the search box at the top of the portal, enter **Microsoft Defender for Cloud**. Select **Microsoft Defender for Cloud** in the search results.
35+
1. Under *General* in the side tab, select **Security alerts**. To filter the alerts list, select your subscription, or any of the relevant filters. You can optionally add filters with the **Add filter** option.
36+
37+
:::image type="content" source="./media/manage-ddos-protection/ddos-protection-security-alerts.png" alt-text="Screenshot of Security alert in Microsoft Defender for Cloud.":::
38+
39+
The alerts include general information about the public IP address that’s under attack, geo and threat intelligence information, and remediation steps.
40+
41+
## Next steps
42+
43+
In this How-To, you learned how to view alerts in Microsoft Defender for Cloud.
44+
45+
To learn how to test and simulate a DDoS attack, see the simulation testing guide:
46+
47+
> [!div class="nextstepaction"]
48+
> [Test through simulations](test-through-simulations.md)
-4.13 KB
Loading

0 commit comments

Comments
 (0)