Separate incremental DDoS reports from the completed mitigation summary

Azure DDoS Protection produces periodic snapshots during mitigation and a distinct report for the whole period afterward.

Resilient network core with engineered blue and gold data paths.
DSE visual intelligenceNetworks & infrastructureGuide · 2 min read
Executive summary

What you need to know

Azure DDoS Protection produces periodic snapshots during mitigation and a distinct report for the whole period afterward.

Potentially affected

Protected Azure public IP resources with DDoS Protection diagnostics configured in Log Analytics.

DSE recommendation

Label interim reports by their observation time and collect the completed mitigation summary before finalizing the incident record.

Source facts

Azure DDoS Protection starts mitigation-report generation when mitigation begins. Microsoft documents incremental reports every five minutes during mitigation and a post-mitigation report covering the complete period. These reports use aggregated Netflow data.

Mitigation flow logs provide a separate near-real-time view of dropped and forwarded traffic during an active attack. The tutorial requires DDoS Network Protection or DDoS IP Protection and configured diagnostic logs. Microsoft Learn.

Applicability

Identify the protected public IP, mitigation interval and configured diagnostic destination. Keep notification, incremental report, completed report and flow-log observations distinct in the evidence record.

DSE recommendation

DSE recommends labeling each interim snapshot with the time and resource it represents. Avoid treating successive snapshots as unrelated completed attacks or presenting an early report as the final total. Assign someone to retrieve and reconcile the post-mitigation report after the event. Keep application-availability observations alongside platform mitigation evidence without assuming the two measure the same outcome.

Verification

During an authorized provider-supported exercise or actual investigation, compare the report sequence with the mitigation start and end. Confirm the final record includes the full-period summary where available and document any collection gap. Use flow logs to investigate the relevant traffic observations without describing them as a complete packet capture. Retain the resource identity and query interval so another reviewer can reproduce the timeline.

Official references

Microsoft Learn: Tutorial: View Azure DDoS Protection logs in Log Analytics workspace. Source retrieved September 9, 2026.

Primary reference

Review the official source

Tutorial: View Azure DDoS Protection logs in Log Analytics workspace | Microsoft Learn · Verified September 9, 2026

Open official reference ↗
Plan the next step

Need help applying this guidance safely?

DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.

Talk with DSE