Description

In some cases, attacks detected by Corero vSWA/SWA may not appear in Corero SSP. This can be expected behavior if the detected attack does not meet the threshold required for SSP to generate and display an attack summary.

Symptoms

You may observe the following:

  • An attack is detected and blocked by vSWA/SWA
  • No corresponding attack information or summary is shown in SSP
  • This may give the impression that SSP is not receiving attack details, even though mitigation has taken place

Solution

This behavior is expected unless the attack meets the minimum criteria for summary generation in SSP.

An attack summary is sent to SSP only when:

  • A single rule blocks more than 1,000 packets per second, or
  • A single rule blocks more than 10 Mbps of traffic

In addition, the vSWA must receive attack samples for at least 1 full minute to generate the summary.

If the blocked traffic does not reach these thresholds or does not continue long enough, an attack summary will not be created, and the event will not be displayed in SSP.

Modification History

2024-12-20 : Article Created