Updated Date: 07/07/2026
Collecting Security Statistics
This implementation describes how to edit the reporting settings for the denial of service (DoS) attack statistics collected from your virtual servers with DoS profile protection. The system can be configured to collect statistics locally or remotely. You use these statistics for troubleshooting and improving DoS protection to your applications or over your network. These statistics include information about the traffic volume, transaction outcomes, packet errors, and IP address information (when available).
When enabling or disabling reporting settings, consider your protection configuration over BIG-IP, and whether your system is currently provisioned with AFM DoS protection coverage (optionally ASM for specific configuration settings).
To collect and report statistics from your DoS protected virtual servers, you must ensure that you have licensed and provisioned the AFM module.
If you would like to store data remotely, ensure that your remote server is configured.
The default reporting settings allows AVR to collect and locally store certain security statistics. You can customize the default reporting and collection settings to your system needs, or to ensure that security reporting is available for storage on a remote publisher. Ensure that the enabled settings meets your custom needs, as increased statistics collection requires additional system resources.
-
On the Main tab, click Security > Reporting > Settings > Reporting Settings.
-
Verify that theLocal Storage setting is Enabled.
This setting prompts the system to store statistics locally, and you can view the charts on the system by starting at the Main tab, and clicking Statistics > Analytics.
-
To export statistics, select Enabled for the Remote Storage setting.
When enabled, you can select the remote storage server from the Publisher setting.
-
Enable or disable the default data collection settings.
For more information about the specific statistics collected, see Reporting settings statistics.
-
To email reports, specify an SMTP Configuration. If no configuration is available, click Create to create one.
-
Click Save.
Statistics are collected from the virtual servers with corresponding security settings.
The reporting settings allow you to configure security statistics collection from virtual servers with network-level (AFM) DoS protection services (unless stated otherwise). The following describes the specific statistics collected per field provided in the Reporting Settings screen (Security > Reporting > Settings > Reporting Settings). Depending on your reporting settings, stored statistics either available locally on your BIG-IP, or on an external server.
All data collected is marked with the reported time stamp, system collection interval, and number of data points collected.
|
Reporting Setting |
Data Collected |
|---|---|
|
Collect ACL stats |
Detected ACL violations are reported as Enforced or Staged, based on the configuration of the corresponding ACL rule list. - Application name
|
|
Remote Storage Only- BIG-IP Hostname and Slot ID
| |
|
Collect Network DoS stats |
|
|
Remote Storage Only- BIG-IP Hostname and Slot ID
| |
|
Collect Firewall Events Stats |
|
|
Remote Storage Only- BIG-IP Hostname and Slot ID
| |
|
Collect IP Reputation stats |
|
|
Remote Storage Only- BIG-IP Hostname and Slot ID
| |
|
Collect DNS stats |
|
|
Remote Storage Only- BIG-IP Hostname and Slot ID
| |
|
Collect SIP stats |
|
|
Remote Storage Only- BIG-IP Hostname and Slot ID
| |
|
DoS Network |
Destination IP address sent over the network |
|
Network Firewall Rules |
|
|
DoS HTTP* |
All HTTP analytics data for virtual servers with ASM DoS protection. For more information about the collected information, go to Local Traffic > Profiles > Analytics > HTTP Analytics and select the analytics profile. |