In some cases, attacks detected by Corero vSWA/SWA may not appear in Corero SSP. This can be expected behavior if the detected attack does not meet the threshold required for SSP to generate and display an attack summary.
You may observe the following:
This behavior is expected unless the attack meets the minimum criteria for summary generation in SSP.
An attack summary is sent to SSP only when:
In addition, the vSWA must receive attack samples for at least 1 full minute to generate the summary.
If the blocked traffic does not reach these thresholds or does not continue long enough, an attack summary will not be created, and the event will not be displayed in SSP.