You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/ddos-protection/alerts.md
+26-17Lines changed: 26 additions & 17 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -4,17 +4,20 @@ description: Learn how to configure DDoS protection metric alerts for Azure DDoS
4
4
services: ddos-protection
5
5
author: AbdullahBell
6
6
ms.service: ddos-protection
7
-
ms.topic: how-to
7
+
ms.topic: tutorial
8
8
ms.custom: ignite-2022
9
9
ms.workload: infrastructure-services
10
-
ms.date: 01/30/2023
10
+
ms.date: 08/07/2023
11
11
ms.author: abell
12
12
---
13
13
# Configure Azure DDoS Protection metric alerts through portal
14
14
15
-
Azure DDoS Protection provides detailed attack insights and visualization with DDoS Attack Analytics. Customers protecting their virtual networks against DDoS attacks have detailed visibility into attack traffic and actions taken to mitigate the attack via attack mitigation reports & mitigation flow logs. Rich telemetry is exposed via Azure Monitor including detailed metrics during the duration of a DDoS attack. Alerting can be configured for any of the Azure Monitor metrics exposed by DDoS Protection. Logging can be further integrated with [Microsoft Sentinel](../sentinel/data-connectors/azure-ddos-protection.md), Splunk (Azure Event Hubs), OMS Log Analytics, and Azure Storage for advanced analysis via the Azure Monitor Diagnostics interface.
15
+
DDoS Protection metrics alerts are an important step in alerting your team through Azure portal, email, SMS message, push, or voice notification when an attack is detected.
16
16
17
-
In this article, you'll learn how to configure metrics alerts through Azure Monitor.
17
+
In this tutorial, you learn how to:
18
+
19
+
> [!div class="checklist"]
20
+
> * Configure metrics alerts through Azure Monitor.
18
21
19
22
20
23
## Prerequisites
@@ -33,11 +36,11 @@ You can select any of the available Azure DDoS Protection metrics to alert you w
33
36
34
37
1. Select **+ Create** on the navigation bar, then select **Alert rule**.
35
38
36
-
:::image type="content" source="./media/manage-ddos-protection/ddos-protection-alert-page.png" alt-text="Screenshot of creating Alerts.":::
39
+
:::image type="content" source="./media/ddos-alerts/ddos-protection-alert-page.png" alt-text="Screenshot of creating Alerts." lightbox="./media/ddos-alerts/ddos-protection-alert-page.png":::
37
40
38
41
1. On the **Create an alert rule** page, select **+ Select scope**, then select the following information in the **Select a resource** page.
@@ -49,10 +52,10 @@ You can select any of the available Azure DDoS Protection metrics to alert you w
49
52
1. Select **Done**, then select **Next: Condition**.
50
53
1. On the **Condition** page, select **+ Add Condition**, then in the *Search by signal name* search box, search and select **Under DDoS attack or not**.
1. On the *Details* tab, under *Alert rule details*, enter the following information.
100
103
@@ -107,7 +110,7 @@ You can select any of the available Azure DDoS Protection metrics to alert you w
107
110
108
111
Within a few minutes of attack detection, you should receive an email from Azure Monitor metrics that looks similar to the following picture:
109
112
110
-
:::image type="content" source="./media/manage-ddos-protection/ddos-alert.png" alt-text="Screenshot of a DDoS Attack Alert.":::
113
+
:::image type="content" source="./media/ddos-alerts/ddos-alert.png" alt-text="Screenshot of a DDoS Attack Alert." lightbox="./media/ddos-alerts/ddos-alert.png":::
111
114
112
115
You can also learn more about [configuring webhooks](../azure-monitor/alerts/alerts-webhooks.md?toc=%2fazure%2fvirtual-network%2ftoc.json) and [logic apps](../logic-apps/logic-apps-overview.md?toc=%2fazure%2fvirtual-network%2ftoc.json) for creating alerts.
113
116
@@ -116,15 +119,21 @@ You can keep your resources for the next tutorial. If no longer needed, delete t
116
119
117
120
1. In the search box at the top of the portal, enter **Alerts**. Select **Alerts** in the search results.
118
121
119
-
:::image type="content" source="./media/manage-ddos-protection/ddos-protection-alert-rule.png" alt-text="Screenshot of Alerts page.":::
122
+
:::image type="content" source="./media/ddos-alerts/ddos-protection-alert-rule.png" alt-text="Screenshot of Alerts page." lightbox="./media/ddos-alerts/ddos-protection-alert-rule.png":::
120
123
121
124
1. Select **Alert rules**.
122
125
123
-
:::image type="content" source="./media/manage-ddos-protection/ddos-protection-delete-alert-rules.png" alt-text="Screenshot of Alert rules page.":::
126
+
:::image type="content" source="./media/ddos-alerts/ddos-protection-delete-alert-rules.png" alt-text="Screenshot of Alert rules page." lightbox="./media/ddos-alerts/ddos-protection-delete-alert-rules.png":::
124
127
125
128
1. In the Alert rules page, select your subscription.
126
129
1. Select the alerts created in this tutorial, then select **Delete**.
127
130
## Next steps
128
131
129
-
*[Test through simulations](test-through-simulations.md)
130
-
*[View alerts in Microsoft Defender for Cloud](ddos-view-alerts-defender-for-cloud.md)
132
+
In this tutorial you learned how to configure metric alerts through Azure portal.
133
+
134
+
To configure diagnostic logging, continue to the next tutorial.
Copy file name to clipboardExpand all lines: articles/ddos-protection/ddos-diagnostic-alert-templates.md
+4-4Lines changed: 4 additions & 4 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -39,7 +39,7 @@ The Azure Monitor alert rule template will run a query against the diagnostic lo
39
39
[](https://portal.azure.com/#create/Microsoft.Template/uri/https%3A%2F%2Fraw.githubusercontent.com%2FAzure%2FAzure-Network-Security%2Fmaster%2FAzure%2520DDoS%2520Protection%2FAlert%2520-%2520DDOS%2520Mitigation%2520started%2520azure%2520monitor%2520alert%2FDDoSMitigationStarted.json)
40
40
41
41
1. On the *Custom deployment* page, under *Project details*, enter the following information.
42
-
:::image type="content" source="./media/manage-ddos-protection/ddos-deploy-alert.png" alt-text="Screenshot of Azure Monitor alert rule template.":::
@@ -65,7 +65,7 @@ This DDoS Mitigation Alert Enrichment template deploys the necessary components
65
65
[](https://portal.azure.com/#create/Microsoft.Template/uri/https%3A%2F%2Fraw.githubusercontent.com%2FAzure%2FAzure-Network-Security%2Fmaster%2FAzure%2520DDoS%2520Protection%2FAutomation%2520-%2520DDoS%2520Mitigation%2520Alert%2520Enrichment%2FEnrich-DDoSAlert.json)
66
66
67
67
1. On the *Custom deployment* page, under *Project details*, enter the following information.
68
-
:::image type="content" source="./media/manage-ddos-protection/ddos-deploy-alert-logic-app.png" alt-text="Screenshot of DDoS Mitigation Alert Enrichment template.":::
0 commit comments