Implemented

Alerts on Specific types of Netflow Traffic in NTA

Not sure this has been requested by someone. I would like to know the timelines if possible to create alerts on specific types of netflow traffic like DNS, UDP, NTP etc. , if it exceeds a specific threshold.

This types of alerts can help to get informs of DDoS attack in advance. If someone has any idea to use Orion as a tool to better protect from DDoS, please share.

Case #1148516 - "Alert for NTA to track DDoS Attacks with DNS, UDP, and NTP traffic

Thanks

Sammy Yau