Cloudflare 提供两种类型的安全警报,以便向您通知安全事件的任何激增情况:
- Security Events Alert(安全事件警报):跨所有在 Security Events 中生成日志条目的服务中,针对激增情况发出警报。
- Advanced Security Events Alert(高级安全事件警报):与安全事件警报类似,支持额外的过滤选项。
有关警报类型及其可用性的详细信息,请参阅警报类型。
要接收安全警报,您必须配置通知。根据您的 Cloudflare 计划,通知可通过电子邮件、PagerDuty 或 webhook 帮助您随时了解 Cloudflare 账户的最新动态。
有关如何设置安全警报通知的说明,请参阅创建通知。
安全警报使用静态阈值,并结合过去六小时内每五分钟一个事件桶的 z-score ↗ 计算。只要 z-score 值高于 3.5 且激增越过 200 个安全事件的阈值,就会触发警报。您不会在同一两个小时的时间范围内收到重复的警报。
Advanced Security Events Alert
Who is it for?Enterprise customers who want to receive alerts about spikes in specific services that generate log entries in Security Events. For more information, refer to WAF alerts.
Other options / filtersA mandatory filters selection is needed when you create a notification policy which includes the list of services and zones that you want to be alerted on.
- You can search for and add domains from your list of Enterprise zones.
- You can choose which services the alert should monitor (Managed Firewall, Rate Limiting, etc.).
- You can filter events by a targeted action.
Enterprise plans.
What should you do if you receive one?Review the information in Security Events to identify any possible attack or misconfiguration.
Additional informationThe mean time to detection is five minutes.
When setting up this alert, you can select the services that will be monitored. Each selected service is monitored separately and can be selected as a filter.
LimitationsSecurity Events (WAF) alerts are not sent for each individual events, but only when a spike in traffic reaches the threshold for an alert to be sent.
These thresholds cannot be configured. Z-score is used to determine the threshold.
Security Events Alert
Who is it for?Business and Enterprise customers who want to receive alerts about spikes across all services that generate log entries in Security Events. For more information, refer to WAF alerts.
Other options / filtersA mandatory filters selection is needed when you create a notification policy which includes the list of zones that you want to be alerted on.
- You can also search for and add domains from your list of business or enterprise zones. The notification will be sent for the domains chosen.
- You can filter events by a targeted action.
Business and Enterprise plans.
What should you do if you receive one?Review the information in Security Events to identify any possible attack or misconfiguration.
Additional informationThe mean time to detection is five minutes.
When setting up this alert, you can select the services that will be monitored. Each selected service is monitored separately.
LimitationsSecurity Events (WAF) alerts are not sent for each individual events, but only when a spike in traffic reaches the threshold for an alert to be sent.
These thresholds cannot be configured. Z-score is used to determine the threshold.