What you need to know
Azure DDoS Protection produces periodic snapshots during mitigation and a distinct report for the whole period afterward.
Potentially affected
Protected Azure public IP resources with DDoS Protection diagnostics configured in Log Analytics.
DSE recommendation
Label interim reports by their observation time and collect the completed mitigation summary before finalizing the incident record.
Source facts
Azure DDoS Protection starts mitigation-report generation when mitigation begins. Microsoft documents incremental reports every five minutes during mitigation and a post-mitigation report covering the complete period. These reports use aggregated Netflow data.
Mitigation flow logs provide a separate near-real-time view of dropped and forwarded traffic during an active attack. The tutorial requires DDoS Network Protection or DDoS IP Protection and configured diagnostic logs. Microsoft Learn.
Applicability
Identify the protected public IP, mitigation interval and configured diagnostic destination. Keep notification, incremental report, completed report and flow-log observations distinct in the evidence record.
DSE recommendation
DSE recommends labeling each interim snapshot with the time and resource it represents. Avoid treating successive snapshots as unrelated completed attacks or presenting an early report as the final total. Assign someone to retrieve and reconcile the post-mitigation report after the event. Keep application-availability observations alongside platform mitigation evidence without assuming the two measure the same outcome.
Verification
During an authorized provider-supported exercise or actual investigation, compare the report sequence with the mitigation start and end. Confirm the final record includes the full-period summary where available and document any collection gap. Use flow logs to investigate the relevant traffic observations without describing them as a complete packet capture. Retain the resource identity and query interval so another reviewer can reproduce the timeline.
Official references
Microsoft Learn: Tutorial: View Azure DDoS Protection logs in Log Analytics workspace. Source retrieved September 9, 2026.
Review the official source
Tutorial: View Azure DDoS Protection logs in Log Analytics workspace | Microsoft Learn · Verified September 9, 2026
Need help applying this guidance safely?
DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.
Talk with DSE