After you create a defense rule for a cluster and enable the defense rule, the defense rule allows, blocks, or generates alerts for the traffic destined for the cluster. You can view the alerts that are generated by the defense rule on the Protection Status tab of the Container Firewall page. This topic describes how to view the details on the Protection Status tab.
Background information
The Protection Status tab displays only the alerts generated by defense rules whose action is set to Block or Alert. If the action of a defense rule is set to Allow, the defense rule does not generate alerts.
Procedure
Log on to the Security Center console. In the top navigation bar, select the region of the asset that you want to manage. You can select China or Outside China.
In the left-side navigation pane, choose .
On the Container Firewall page, click the Protection Status tab.
On the Protection Status tab, view the details.
The Protection Status tab displays defense statistics and the alert list.
Defense statistics
You can view the defense statistics in the following sections: Risks in Previous 24 Hours, Risks in Previous 30 Days, Risks in Previous 180 Days, Unprotected Clusters/Total Clusters, and Rules.
Alert list
You can view the alerts that are sorted by generation time in reverse chronological order. All the alerts are generated by the defense rules whose action is set to Alert or Block. If alerts are generated for the same source pod, destination pod, port number, and cluster on the same calendar day, the number of alerts is calculated as 1, and the number of times of access attempts is displayed in the Attempts column.
You can find an alert and click Edit Rule in the Actions column to modify the action of the defense rule that generated the alert. You can also click the icon on the right of Edit Rule to modify the action of the defense rule.
NoteThe modification on the defense rule takes effect within 1 minute.