{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-323-separate-incremental-ddos-reports-from-the-completed-mitigation-summary/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260909-323-separate-incremental-ddos-reports-from-the-completed-mitigation-summary/",
        "slug": "dse-20260909-323-separate-incremental-ddos-reports-from-the-completed-mitigation-summary",
        "url": "https://update.dsesecurity.com/updates/dse-20260909-323-separate-incremental-ddos-reports-from-the-completed-mitigation-summary/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260909-323-separate-incremental-ddos-reports-from-the-completed-mitigation-summary.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-323-separate-incremental-ddos-reports-from-the-completed-mitigation-summary/"
        },
        "title": "Separate incremental DDoS reports from the completed mitigation summary",
        "summary": "Azure DDoS Protection produces periodic snapshots during mitigation and a distinct report for the whole period afterward.",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "network-infrastructure",
            "label": "Networks & infrastructure",
            "alt": "Resilient network core with engineered blue and gold data paths.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "cybersecurity",
                "name": "Cybersecurity",
                "url": "https://update.dsesecurity.com/topic/cybersecurity/"
            },
            {
                "slug": "networks-infrastructure",
                "name": "Networks & Infrastructure",
                "url": "https://update.dsesecurity.com/topic/networks-infrastructure/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-10T00:26:33+00:00",
        "modified_at": "2026-09-10T01:40:03+00:00",
        "reviewed_on": "2026-09-09",
        "reading_minutes": 2,
        "word_count": 234,
        "potentially_affected": "Protected Azure public IP resources with DDoS Protection diagnostics configured in Log Analytics.",
        "dse_recommendation": "Label interim reports by their observation time and collect the completed mitigation summary before finalizing the incident record.",
        "primary_source": {
            "name": "Tutorial: View Azure DDoS Protection logs in Log Analytics workspace | Microsoft Learn",
            "url": "https://learn.microsoft.com/en-us/azure/ddos-protection/ddos-view-diagnostic-logs",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>Azure DDoS Protection starts mitigation-report generation when mitigation begins. Microsoft documents incremental reports every five minutes during mitigation and a post-mitigation report covering the complete period. These reports use aggregated Netflow data.</p>\n<p>Mitigation flow logs provide a separate near-real-time view of dropped and forwarded traffic during an active attack. The tutorial requires DDoS Network Protection or DDoS IP Protection and configured diagnostic logs. <a href=\"https://learn.microsoft.com/en-us/azure/ddos-protection/ddos-view-diagnostic-logs\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<h2>Applicability</h2>\n<p>Identify the protected public IP, mitigation interval and configured diagnostic destination. Keep notification, incremental report, completed report and flow-log observations distinct in the evidence record.</p>\n<h2>DSE recommendation</h2>\n<p>DSE recommends labeling each interim snapshot with the time and resource it represents. Avoid treating successive snapshots as unrelated completed attacks or presenting an early report as the final total. Assign someone to retrieve and reconcile the post-mitigation report after the event. Keep application-availability observations alongside platform mitigation evidence without assuming the two measure the same outcome.</p>\n<h2>Verification</h2>\n<p>During an authorized provider-supported exercise or actual investigation, compare the report sequence with the mitigation start and end. Confirm the final record includes the full-period summary where available and document any collection gap. Use flow logs to investigate the relevant traffic observations without describing them as a complete packet capture. Retain the resource identity and query interval so another reviewer can reproduce the timeline.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/azure/ddos-protection/ddos-view-diagnostic-logs\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Tutorial: View Azure DDoS Protection logs in Log Analytics workspace</a>. Source retrieved September 9, 2026.</p>",
        "content_text": "Source facts\nAzure DDoS Protection starts mitigation-report generation when mitigation begins. Microsoft documents incremental reports every five minutes during mitigation and a post-mitigation report covering the complete period. These reports use aggregated Netflow data.\nMitigation flow logs provide a separate near-real-time view of dropped and forwarded traffic during an active attack. The tutorial requires DDoS Network Protection or DDoS IP Protection and configured diagnostic logs. Microsoft Learn.\nApplicability\nIdentify the protected public IP, mitigation interval and configured diagnostic destination. Keep notification, incremental report, completed report and flow-log observations distinct in the evidence record.\nDSE recommendation\nDSE recommends labeling each interim snapshot with the time and resource it represents. Avoid treating successive snapshots as unrelated completed attacks or presenting an early report as the final total. Assign someone to retrieve and reconcile the post-mitigation report after the event. Keep application-availability observations alongside platform mitigation evidence without assuming the two measure the same outcome.\nVerification\nDuring an authorized provider-supported exercise or actual investigation, compare the report sequence with the mitigation start and end. Confirm the final record includes the full-period summary where available and document any collection gap. Use flow logs to investigate the relevant traffic observations without describing them as a complete packet capture. Retain the resource identity and query interval so another reviewer can reproduce the timeline.\nOfficial references\nMicrosoft Learn: Tutorial: View Azure DDoS Protection logs in Log Analytics workspace. Source retrieved September 9, 2026.",
        "content_markdown": "## Source facts\n\nAzure DDoS Protection starts mitigation-report generation when mitigation begins. Microsoft documents incremental reports every five minutes during mitigation and a post-mitigation report covering the complete period. These reports use aggregated Netflow data.\n\nMitigation flow logs provide a separate near-real-time view of dropped and forwarded traffic during an active attack. The tutorial requires DDoS Network Protection or DDoS IP Protection and configured diagnostic logs. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/ddos-protection/ddos-view-diagnostic-logs).\n\n## Applicability\n\nIdentify the protected public IP, mitigation interval and configured diagnostic destination. Keep notification, incremental report, completed report and flow-log observations distinct in the evidence record.\n\n## DSE recommendation\n\nDSE recommends labeling each interim snapshot with the time and resource it represents. Avoid treating successive snapshots as unrelated completed attacks or presenting an early report as the final total. Assign someone to retrieve and reconcile the post-mitigation report after the event. Keep application-availability observations alongside platform mitigation evidence without assuming the two measure the same outcome.\n\n## Verification\n\nDuring an authorized provider-supported exercise or actual investigation, compare the report sequence with the mitigation start and end. Confirm the final record includes the full-period summary where available and document any collection gap. Use flow logs to investigate the relevant traffic observations without describing them as a complete packet capture. Retain the resource identity and query interval so another reviewer can reproduce the timeline.\n\n## Official references\n\n[Microsoft Learn: Tutorial: View Azure DDoS Protection logs in Log Analytics workspace](https://learn.microsoft.com/en-us/azure/ddos-protection/ddos-view-diagnostic-logs). Source retrieved September 9, 2026."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-323-separate-incremental-ddos-reports-from-the-completed-mitigation-summary/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-323-separate-incremental-ddos-reports-from-the-completed-mitigation-summary/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-09"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-323-separate-incremental-ddos-reports-from-the-completed-mitigation-summary/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Separate incremental DDoS reports from the completed mitigation summary",
                        "item": "https://update.dsesecurity.com/updates/dse-20260909-323-separate-incremental-ddos-reports-from-the-completed-mitigation-summary/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-323-separate-incremental-ddos-reports-from-the-completed-mitigation-summary/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260909-323-separate-incremental-ddos-reports-from-the-completed-mitigation-summary/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-323-separate-incremental-ddos-reports-from-the-completed-mitigation-summary/",
                "headline": "Separate incremental DDoS reports from the completed mitigation summary",
                "description": "Azure DDoS Protection produces periodic snapshots during mitigation and a distinct report for the whole period afterward.",
                "abstract": "Azure DDoS Protection produces periodic snapshots during mitigation and a distinct report for the whole period afterward.",
                "articleBody": "Source facts\nAzure DDoS Protection starts mitigation-report generation when mitigation begins. Microsoft documents incremental reports every five minutes during mitigation and a post-mitigation report covering the complete period. These reports use aggregated Netflow data.\nMitigation flow logs provide a separate near-real-time view of dropped and forwarded traffic during an active attack. The tutorial requires DDoS Network Protection or DDoS IP Protection and configured diagnostic logs. Microsoft Learn.\nApplicability\nIdentify the protected public IP, mitigation interval and configured diagnostic destination. Keep notification, incremental report, completed report and flow-log observations distinct in the evidence record.\nDSE recommendation\nDSE recommends labeling each interim snapshot with the time and resource it represents. Avoid treating successive snapshots as unrelated completed attacks or presenting an early report as the final total. Assign someone to retrieve and reconcile the post-mitigation report after the event. Keep application-availability observations alongside platform mitigation evidence without assuming the two measure the same outcome.\nVerification\nDuring an authorized provider-supported exercise or actual investigation, compare the report sequence with the mitigation start and end. Confirm the final record includes the full-period summary where available and document any collection gap. Use flow logs to investigate the relevant traffic observations without describing them as a complete packet capture. Retain the resource identity and query interval so another reviewer can reproduce the timeline.\nOfficial references\nMicrosoft Learn: Tutorial: View Azure DDoS Protection logs in Log Analytics workspace. Source retrieved September 9, 2026.",
                "datePublished": "2026-09-10T00:26:33+00:00",
                "dateModified": "2026-09-10T01:40:03+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-323-separate-incremental-ddos-reports-from-the-completed-mitigation-summary/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-323-separate-incremental-ddos-reports-from-the-completed-mitigation-summary/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Separate incremental DDoS reports from the completed mitigation summary"
                },
                "articleSection": [
                    "Cybersecurity",
                    "Networks & Infrastructure"
                ],
                "keywords": [
                    "Cybersecurity",
                    "Networks & Infrastructure",
                    "Guide",
                    "Information priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Cybersecurity",
                        "url": "https://update.dsesecurity.com/topic/cybersecurity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "Networks & Infrastructure",
                        "url": "https://update.dsesecurity.com/topic/networks-infrastructure/"
                    }
                ],
                "wordCount": 234,
                "timeRequired": "PT2M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Tutorial: View Azure DDoS Protection logs in Log Analytics workspace | Microsoft Learn",
                    "url": "https://learn.microsoft.com/en-us/azure/ddos-protection/ddos-view-diagnostic-logs"
                }
            }
        ]
    }
}