Bug ID 446272: In some rare cases, the Network DoS analytics report is empty while the Network DoS log does have attack entries

Last Modified: Sep 13, 2023

Affected Product(s):
BIG-IP AFM, AVR(all modules)

Known Affected Versions:
11.5.0, 11.5.1, 11.5.2, 11.5.3, 11.5.4, 11.5.5, 11.5.6, 11.5.7, 11.5.8, 11.5.9, 11.5.10, 11.6.0, 11.6.1, 11.6.2, 11.6.3,,,,, 11.6.4, 11.6.5,,,, 12.1.0 HF1, 12.1.0 HF2, 12.1.1 HF1, 12.1.1 HF2, 12.1.2 HF1, 12.1.2 HF2

Fixed In:

Opened: Jan 25, 2014

Severity: 4-Minor


When a virtual server is deleted right after an attack has taken place, the statistics for that attack won't be visible in the Network DoS analytics report.


Statistics from the last 5 minutes won't be visible.


The virtual server on which we are running traffic has to be deleted a minute or two before statistics are written to the analytics database.



Fix Information

The network DoS analytics report is no longer empty while the network DoS log has attack entries.

Behavior Change

Guides & references

K10134038: F5 Bug Tracker Filter Names and Tips