DNS¶
Overview¶
Module Name in API¶
dns
Product Name in API¶
local-traffic
Dimensions¶
Dimension | Name in API | Description |
---|---|---|
Country | country | Client Country |
Virtual Server | virtual | |
DOS Profile | dos-profile-name | Name of the DoS profile used in the BIG-IP |
BIG-IP Blade Number | slot-id | Used for BIG-IP Chassis with multiple blades. A value of 0 means this is a non chassis BIG-IP, any other value tells the serial number of the blade in the chassis |
Attack Mitigation | attack-mitigation | The current method of mitigation taken by the BIG-IP to handle the attack |
Transaction Outcome | transaction-outcome | Tells how the transaction was resulted, whether it was succeeded, blocked, got terminated due to connection reset, etc. |
Query Type | query-type | |
Internal Activity indication | is-internal-activity | Internal activity stands for transactions that are generated by BIG-IP own activity, such as injected JS, in conjunction with transactions generated by the user activity |
Domain Name | query-name | |
Attack Vector | attack-vector | |
Client IP | client-ip | |
DataCenter Name | datacenter-name | |
DataCenter | datacenter | |
Attack Trigger | attack-trigger | Tells what triggered the BIG-IP to declare this attack |
BIG-IP Host Name | hostname | The hostname given to the BIG-IP |
Attack ID | attack-id | A code provided by BIG-IP to this attack, the ID is per BIG-IP and should not be confused with combined attack ID of multiple BIG-IPs |
Virtual Server Unique Name | unique-virtual-name | Virtual server full name connected to a device or cluster name |
BIG-IP Service Cluster | dsc-name | Clusters of BIG-IPs grouped together to have the same config |
IP Type | ip-type | Tells whether client IP is IPv4 or IPv6 |
DataCenter Location | datacenter-location |
MetricSets¶
Transactions¶
Description¶
Number of transactions
Name In API¶
transactions
Metrics in the metricSet¶
Metric | Name in API | Unit | Description |
---|---|---|---|
Total Transactions Count | count | trans | Total number of transactions that passed through the system |
Avg TPS | avg-count-per-sec | tps | Average number of transactions that passed through the system per second |
Examples¶
By Time Query¶
A query by time returns a series of data points in time, based on optional filters, time range, and time granularity. This query kind is identified by the keyword: “ap:query:stats:byTime”
POST https://<address>/mgmt/ap/query/v1/tenants/default/products/local-traffic/metric-query
This example for JSON body in the post, filters by dimension country and get the count of transactions
{
"kind": "ap:query:stats:byTime",
"module": "dns",
"timeRange": {
"from": "-1h",
"to": "now"
},
"timeGranularity": {
"duration": 30,
"unit": "SECONDS"
},
"aggregations": {
"transactions$count": {
"metricSet": "transactions",
"metric": "count"
}
},
"dimensionFilter": {
"type": "eq",
"dimension": "country",
"value": "value to filter by"
}
}
By Entities Query¶
A query by entities returns a sort set of entities, based on optional filters, time range, and choosen metric to sort by. This query kind is identified by the keyword: “ap:query:stats:byEntities”
POST https://<address>/mgmt/ap/query/v1/tenants/default/products/local-traffic/metric-query
This example for JSON body in the post, gets top entities of type country, sorted by count of transactions
{
"kind": "ap:query:stats:byEntities",
"module": "dns",
"timeRange": {
"from": "-1H",
"to": "now"
},
"dimension": "country",
"sortMetric": "transactions$count",
"sortOrder": "desc",
"aggregations": {
"transactions$count": {
"metricSet": "transactions",
"metric": "count"
}
},
"limit": 5
}
Entities Count Query¶
An entities count query returns the distinct count of entities, based on optional filters, time range, and choosen entity type. This query kind is identified by the keyword: “ap:query:stats:entitiesCount”
POST https://<address>/mgmt/ap/query/v1/tenants/default/products/local-traffic/metric-query
This example for JSON body in the post, gets the distinct count of entities of type country
{
"kind": "ap:query:stats:entitiesCount",
"module": "dns",
"dimension": "country",
"timeRange": {
"from": "-1h",
"to": "now"
}
}