Skip to main content
The events log stores DDoS attacks and related incidents from the past three months in the Gcore Customer Portal. This page covers that log and attack email notifications. Live attack statistics stay on the Overview dashboard.

Events log

Each row is one incident. Open a row for traffic graphs and a source breakdown.
1

Open the events log

In the Customer Portal, navigate to DDoS ProtectionReportsEvents log.
DDoS Protection sidebar with Events log selected under Reports
2

Find an incident

Use Search by Target IP, the date range, and the Show all event-type filter to narrow the list. Adjust Entries per page and pagination when the log spans more than one page.
Events log table with search, date filter, Show all, and DDoS Attack rows
BPS and PPS are the instantaneous rates measured at detection, after filtering has already started. Because part of the flood is suppressed by that point, these values can read lower than the graphs in event details, which reflect the full incident.
A DDoS Attack row is a detected flood. An RTBH row is a remotely triggered black hole that null-routes the target IP until the block lifts.

Event details

Click an event to open attack details for that incident. The view combines a traffic-volume graph with breakdowns by country, IP, port, and protocol.
DDoS Attack details with the Network traffic graph selected
The tabs are:
  • Network traffic shows volume during the incident.
  • Packet sizes shows how packet sizes were distributed.
  • Top source countries lists countries that generated the most traffic.
  • Top source IPs lists source addresses that generated the most traffic.
  • Top source ports lists source ports used in the attack.
  • Top destination ports lists destination ports the attack targeted.
  • Top protocols lists protocols used in the attack.

Attack email notifications

Gcore sends attack and IP-block emails to the account’s registered address, once Protected Network notifications is turned on in notification settings. A follow-up attack that starts while the IP is still null-routed does not generate a second email, so a quiet inbox during a prolonged block does not mean the attack stopped. If an expected alert is missing, check the spam folder first, then confirm the registered address in the Customer Portal.