# Separate incremental DDoS reports from the completed mitigation summary

> Azure DDoS Protection produces periodic snapshots during mitigation and a distinct report for the whole period afterward.

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-323-separate-incremental-ddos-reports-from-the-completed-mitigation-summary/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:26:33+00:00
- Modified: 2026-09-10T01:40:03+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: Cybersecurity, Networks & Infrastructure
- Reading time: 2 minutes

## What you need to know

Azure DDoS Protection produces periodic snapshots during mitigation and a distinct report for the whole period afterward.

## Potentially affected

Protected Azure public IP resources with DDoS Protection diagnostics configured in Log Analytics.

## DSE recommendation

Label interim reports by their observation time and collect the completed mitigation summary before finalizing the incident record.

## Article

## Source facts

Azure DDoS Protection starts mitigation-report generation when mitigation begins. Microsoft documents incremental reports every five minutes during mitigation and a post-mitigation report covering the complete period. These reports use aggregated Netflow data.

Mitigation flow logs provide a separate near-real-time view of dropped and forwarded traffic during an active attack. The tutorial requires DDoS Network Protection or DDoS IP Protection and configured diagnostic logs. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/ddos-protection/ddos-view-diagnostic-logs).

## Applicability

Identify the protected public IP, mitigation interval and configured diagnostic destination. Keep notification, incremental report, completed report and flow-log observations distinct in the evidence record.

## DSE recommendation

DSE recommends labeling each interim snapshot with the time and resource it represents. Avoid treating successive snapshots as unrelated completed attacks or presenting an early report as the final total. Assign someone to retrieve and reconcile the post-mitigation report after the event. Keep application-availability observations alongside platform mitigation evidence without assuming the two measure the same outcome.

## Verification

During an authorized provider-supported exercise or actual investigation, compare the report sequence with the mitigation start and end. Confirm the final record includes the full-period summary where available and document any collection gap. Use flow logs to investigate the relevant traffic observations without describing them as a complete packet capture. Retain the resource identity and query interval so another reviewer can reproduce the timeline.

## Official references

[Microsoft Learn: Tutorial: View Azure DDoS Protection logs in Log Analytics workspace](https://learn.microsoft.com/en-us/azure/ddos-protection/ddos-view-diagnostic-logs). Source retrieved September 9, 2026.

## Primary reference

- Name: Tutorial: View Azure DDoS Protection logs in Log Analytics workspace | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/azure/ddos-protection/ddos-view-diagnostic-logs
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Separate incremental DDoS reports from the completed mitigation summary,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-323-separate-incremental-ddos-reports-from-the-completed-mitigation-summary/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
