Attacked Destinations Report
Every 5 minutes, FortiDDoS generates a text/CSV file listing the top 20 destination IPs (Protected IPs) with the most drops. It keeps 24 files (2 hours of data) and continuously replaces the oldest with the latest. You can view this data in the GUI or download a CSV by clicking on any row or checkbox for more details.
The GUI view and CSV are formatted like this:
IP, Drop Count, SPP Name
1.1.1.2,16127102,WEB_SERVICES
1.0.0.129,277923,WEB_SERVICES
4.1.1.129,275771,FTP_SERVICES
3.0.0.129,271764,spp01
2.0.31.164,244447,WEB_SERVICES
2.0.0.188,241864,WEB_SERVICES
2.0.9.233,241097,WEB_SERVICES
These files are intended to assist MSSPs and ISPs when under heavy flooding since they need to provide the attacked IP(s) to upstream ISPs for mitigation.