GlobePEER Threat Insights Tutorial

Christian Petrasch Updated by Christian Petrasch

This article shows how to use the Service Insights system to monitor traffic, detect issues, and answer key network questions for our Standard customers, defined as those who neither resell services nor operate a DE-CIX as a service (DaaS) location.

  

General hints about the usage of Service Insights can be found at: Service Insights Tutorial - General Informations

Am I suffering a DDoS attack?

For evaluating DDoS attacks in your traffic, navigate to the GlobePeer DDoS Traffic Insights and enter the section DDoS Analytics Insights.

The dashboard shows you the possible DDoS traffic share of your flow traffic and in the flow (sankey) graph you can see which are your top-talkers.

You can choose the filters in filter section for more specific details.

Choose the service IP you want to see in combination of a high confidence in DDoS Confidence filter. If you will see some high traffic loads then our system is detecting a possible DDoS attack against this/these service IP(s).

 

When I blackhole traffic for one more more prefixes, how can I see metrics of that traffic?

For evaluating Blackholing traffic, navigate to the GlobePeer Threat Insights and enter the section Blackhole Traffic Insights.

 

The dashboard shows you insights about blackholing traffic like:

  • Number of blackholed rules and which rules are matching (BH Rules and Traffic Information dashboard)
  • Traffic and packets per rule (BH Rules and Traffic Information dashboard)
  • Blackholed connections traffic volume Top 50 (BH Rules and Traffic Information dashboard)
  • Geographic distribution per packet source (Geographic Distribution dashboard)
  • IP/port distribution pie charts(IP and Port Distribution dashboard)

 

 

 

Need help? Get in touch with our customer service.

How did we do?

GlobePEER Traffic Insights Tutorial

Get in touch