• Company
    • About Us
    • Case Studies
    • Press Center
    • Events
    • Careers
    • Blog
    • Contact us
  • Contact us
  • Login
 
  • English
    • Deutsch
    • Español
    • Français
    • Italiano
    • Português
Paessler
                    - The Monitoring Experts
  • Products
    • Paessler PRTG
      Paessler PRTGMonitor your whole IT infrastructure
      • PRTG Network Monitor
      • PRTG Enterprise Monitor
      • PRTG Hosted Monitor
      • PRTG extensionsExtensions for Paessler PRTGExtend your monitoring to a new level
    • Icon Features
      FeaturesExplore all monitoring features
      • Maps & dashboards
      • Alerts & notifications
      • Multiple user interfaces
      • Distributed monitoring
      • Customizable reporting
  • Solutions
    • Industries
      IndustriesMonitor various industry sectors
      • Industrial
      • Healthcare
      • Data Center
      • Education
      • Finance
      • Government
    • IT Topics
      IT TopicsMonitor all areas of IT
      • Network Monitoring
      • Bandwidth Monitoring
      • SNMP Monitor
      • Network Mapping
      • WiFi Monitoring
      • Server Monitoring
  • Pricing
  • Resources
    • Getting Started
      Getting StartedModules for self-paced learning
    • How-to Guides
      How-to GuidesGet the most out of PRTG
    • Videos & Webinars
      Videos & WebinarsLearn from Paessler experts
    • IT  Knowledge
      IT KnowledgeExpand your IT knowledge
    • PRTG Manual
      PRTG ManualFull documentation
    • Knowledge Base
      Knowledge BaseShare community knowledge
    • PRTG Sensor Hub
      PRTG Sensor HubGet sensors, scripts & templates
    • Trainings
      PRTG TrainingLearn how to work with PRTG
  • Partners
    • icon star
      New Partners and MSPBecome a new partner or MSP
    • icon partner
      Partner PortalLog in to your partner account
    • Deal Registration
      Deal RegistrationRegister your sales opportunities
    • icon search
      Find a PartnerFind partners selling Paessler products
    • icon technology
      Technology AlliancesSee Paessler technology partnerships
  • Company
    • About Us
    • Case Studies
    • Press Center
    • Events
    • Careers
    • Blog
    • Contact us
  • Contact us
  • Login
  • English
    • Deutsch
    • Español
    • Français
    • Italiano
    • Português
  • Get a quote
  • Free trial
  1. Home>
  2. IT Topics>
  3. Security>
  4. DDoS Monitoring
PRTG Logo

DDoS Monitoring with PRTG

Keep distributed denial of service attacks at bay with real-time monitoring 

  • Spot suspicious traffic patterns before attackers can take down your services
  • Get instant alerts when something fishy is happening on your network
  • See exactly what's going on during an attack so you can fight back effectively
Free download
product overview

Our users give top ratings for monitoring with Paessler PRTG

Gartner peer insights
spiceworks
G2
Capterra

PRTG DDoS monitoring: What you will find on this page

Table of content
  • Why DDoS monitoring with PRTG matters for your network
  • What DDoS monitoring looks like in PRTG
  • 3 ways PRTG can provide effective DDoS monitoring
  • Explore our preconfigured PRTG sensors for DDoS monitoring
  • DDoS Monitoring: FAQ

PRTG makes DDoS Monitoring as easy as it gets

Custom alerts and data visualization let you quickly identify and prevent malicious traffic patterns.

Free download
PRODUCT OVERVIEW

Why DDoS monitoring with PRTG matters for your network

DDoS attacks have evolved from simple nuisances to sophisticated cybersecurity threats that can seriously impact your infrastructure. Without proper monitoring, these attacks can slip under the radar until it's too late – before you know it, your services are down, and you have big problems. Proactive DDoS monitoring with Paessler PRTG gives you the edge you need to stay one step ahead of attackers.

icon thief

Detect attacks before they cause downtime

The key to effective DDoS mitigation is early detection. PRTG continuously monitors your network traffic, establishing baseline metrics for what's "normal" in your environment. When traffic patterns deviate from this baseline, you'll know immediately – often before users notice any performance issues. PRTG helps you identify the attack type so you can implement the right response strategy quickly.

icon trojan

Distinguish between legitimate traffic spikes and attacks

Not every traffic spike means you're under attack. PRTG helps you sort the regular traffic from the malicious attacks. By analyzing traffic patterns, protocol distribution, and source IP addresses, PRTG gives you the context you need to make informed decisions.

icon firewall

Strengthen your firewall and security infrastructure

Your firewall is your first line of defense against DDoS attacks, but it needs proper monitoring to be truly effective. PRTG helps you optimize your firewall configuration and implement rate limiting to better withstand attacks while ensuring legitimate users can still access your services.

icon protection

Monitor your DDoS protection strategy

PRTG gives you valuable insights into your network traffic patterns that can help you evaluate how well your DDoS protection measures are performing. By monitoring key metrics before, during, and after attack events, you can monitor critical services to ensure they remain available to legitimate users.

What DDoS monitoring looks like in PRTG

Diagnose network issues by continuously tracking bandwidth usage and traffic patterns. Show protocol-specific metrics and other key indicators in real time. Visualize monitoring data in clear graphs and dashboards to identify problems more easily. Gain the overview you need to troubleshoot potential threats and avoid disruptions before they impact your business.

PRTG Screenshot device tree view

Device tree view of the complete monitoring setup

PRTG screenshot of the Packet Sniffer Sensor

Toplist details in the PRTG Packet Sniffer Sensor

PRTG screenshot graph live data traffic

Live traffic data graph in PRTG

Start DDoS monitoring with PRTG and see how it can make your network more reliable and your job easier.

Free download
PRODUCT OVERVIEW

IT experts agree: Paessler PRTG is a great solution for IT infrastructure monitoring

PCMag

“All-around winning
 network monitor”

IT Brief

“The real beauty of PRTG is the endless possibilities it offers”

ITPro

“PRTG Network Monitor 
is very hard to beat”

3 ways PRTG can provide effective DDoS monitoring

With a combination of real-time monitoring, intelligent alerting and comprehensive visibility, PRTG transforms DDoS detection from a reactive scramble into a proactive security strategy giving you precious time to implement countermeasures before services are impacted.

icon boost

Create a multi-layered monitoring approach

Effective DDoS monitoring requires visibility at multiple levels of your network. PRTG enables you to create a layered monitoring strategy that can detect different types of DDoS attacks. Monitor internet-facing routers and firewalls for volumetric attacks, or track web server and DNS performance for signs of application layer attacks. You can also keep an eye on internal network segments for unusual traffic patterns that might indicate malware or botnet activity.

icon alarm

Custom alerting to reduce false positives

PRTG's flexible notification system lets you create alert conditions that reduce noise. You can implement alert dependencies to prevent notification storms during large-scale events, or create multi-condition alerts that trigger only when specific conditions indicate an attack - ensuring you're only notified about genuine threats.

icon dashboard

Visualize attack patterns with custom dashboards

When you're responding to a potential DDoS attack, you need clear, actionable information at a glance. By setting up geographic maps showing attack source locations, or building dedicated DDoS monitoring dashboards showing critical metrics, PRTG helps you create a visual command center for DDoS monitoring and response.

Explore our preconfigured PRTG sensors for DDoS monitoring

PRTG comes with more than 250 native sensor types for monitoring your entire on-premises, cloud, and hybrid cloud environment out of the box. Check out some examples below!

SNMP Traffic v2

The SNMP Traffic v2 sensor monitors bandwidth and traffic on a device. It can show the following:

  • Number of incoming and outgoing broadcast, multicast, unicast, and non-unicast packets
  • Number of incoming and outgoing discards and errors
  • Total, incoming, and outgoing traffic
  • Number of incoming, unknown protocols
SNMP Traffic v2
SNMP Traffic v2

Packet Sniffer

The Packet Sniffer sensor monitors the headers of data packets that pass a local network card using a built-in packet sniffer. You can choose from predefined channels. It can show the following and more:

  • Traffic from Citrix applications
  • Traffic from file transfer (FTP/P2P) and various other protocols (UDP, TCP)
  • Traffic from network services (DHCP, DNS, Ident, ICMP, SNMP)
  • Internet mail traffic (IMAP, POP3, SMTP)
  • Traffic from remote control applications (RDP, SSH, Telnet, Virtual Network Computing (VNC))
Packet Sniffer
Packet Sniffer

NetFlow v9

The NetFlow v9 sensor receives traffic data from a NetFlow v9-compatible device and shows the traffic by type. This sensor has several filter options to divide traffic into different channels. It can show the following and more:

  • Traffic from Citrix applications
  • Traffic from file transfer (FTP/P2P) and various other protocols (UDP, TCP)
  • Traffic from network services (DHCP, DNS, Ident, ICMP, SNMP)
  • Internet mail traffic (IMAP, POP3, SMTP)
  • Traffic from remote control applications (RDP, SSH, Telnet, Virtual Network Computing (VNC))
NetFlow v9
NetFlow v9

DNS v2

The DNS v2 sensor monitors a Domain Name System (DNS) server, resolves domain name records, and compares them to a filter. It can show the following:

  • Number of matched records (if you use a filter)
  • Number of records
  • If records were resolved
  • Response time
DNS v2
DNS v2

SNMP Custom Advanced

The SNMP Custom Advanced sensor monitors numeric values returned for object identifiers (OID). It can show the following:

  • Downtime
  • Numeric value for a specified OID (up to 10 OIDs are possible) that refers to a specific SNMP device
SNMP Custom Advanced
SNMP Custom Advanced

See the PRTG Manual for a list of all available sensor types.

PRTG is compatible with all major vendors, products, and systems

compatible with all major vendors, products, and systems

PRTG makes DDoS monitoring as easy as it gets

Custom alerts and data visualization let you quickly identify and prevent malicious traffic patterns.

Free download
PRODUCT OVERVIEW

”PRTG helps us monitor critical security systems to give customers the peace of mind that their devices are operational and protecting their valuable assets.”

Rob Jackson, President
Integrated Precision Systems

“When it comes to security, we do of course use classic tools such as firewalls, virus scanners, and intrusion detection systems. However, these are no longer enough today. PRTG provides for additional security by detecting unusual behavior which may be a sign that a hacker has outsmarted our security systems.”

Damir Karacic, IT Administrator
Noris Inklusion

“Monitoring with PRTG is crucial for security. Today’s threats can move low and slow, so in addition to looking at the usual suspects, you also need to keep tabs on other indicators. For example, if a server is running a peak capacity for no apparent reason, you want to know so you can take a look and see what’s up – for example an open connection that is being used to extract data in a ransomware attack.”

Jon Larsen, CIO
Richweb

“The best thing about PRTG is that it provides for simple and effective monitoring, all the while respecting the security requirements of manufacturers. PRTG is so easy to use, that many of our monitoring tasks are now handled by our interns. We will definitely expand our use of the software in the future.”

Karsten Boettger, Head of IT
LAKUMED Clinics

Your DDoS monitor at a glance – even on the go

PRTG is set up in a matter of minutes and can be used on a wide variety of mobile devices.

device overview
Gartner peer insights

“Excellent tool for detailed monitoring. Alarms and notifications work greatly. Equipment addition is straight forward and server initial setup is very easy. ...feel safe to purchase it if you intend to monitor a large networking landscape.”

Read the complete review at Gartner Peer Insights

Create innovative solutions with Paessler’s IT partners

Partnering with innovative IT vendors, Paessler unleashes synergies to create
new and additional benefits for joined customers.

baramundi

baramundi

baramundi and PRTG create a secure, reliable and powerful IT infrastructure where you have everything under control - from the traffic in your firewall to the configuration of your clients.

Read more
KnowledgeRiver

KnowledgeRiver

Combining their tools to a powerful solution for advanced analysis and automation, KnowledgeRiver and Paessler enable IT teams to ensure best performance for their infrastructure and networks.

Read more
NetBrain

NetBrain

Integrating monitoring results from PRTG into NetBrain maps makes the foundation for network automation.

Read more

Find the root cause of the problem with our PRTG DDoS monitoring solution

Real-time notifications mean faster troubleshooting so that you can act before more serious issues occur.

Free download
PRODUCT OVERVIEW
Paessler PRTG

Paessler PRTG

Network Monitoring Software – Version 25.2.106.1114 (July 2, 2025)

Hosting icon

Hosting

Download for Windows and cloud-based version PRTG Hosted Monitor available

Languages icon

Languages

English, German, Spanish, French, Portuguese, Dutch, Russian, Japanese, and Simplified Chinese

test

Monitor everything

Network devices, bandwidth, servers, applications, virtual environments, remote systems, IoT, and more

test

Pricing

Choose the PRTG Network Monitor subscription that's best for you

DDoS Monitoring: FAQ

 

What exactly is a DDoS attack?

A distributed denial of service (DDoS) attack is when attackers use multiple compromised computers (often thousands at once in what's called a botnet) to flood your systems with traffic. It's like having thousands of people try to squeeze through your office door at once – nobody gets in, and legitimate users can't access your services. These attacks can target your network bandwidth, server resources, or specific applications.

What types of DDoS attacks are there?

DDoS attacks generally come in three main varieties:

  • Volumetric attacks: These are the brute force attacks that simply try to use up all your bandwidth. Common examples include UDP floods (sending tons of UDP packets to random ports) and ICMP floods (overwhelming your network with ping requests).
  • Protocol attacks: These are a bit more sophisticated and target server resources or networking equipment by exploiting how protocols work. SYN floods (sending many connection requests without completing them) and fragmented packet attacks (sending malformed packets that can't be reassembled) are common examples.
  • Application layer attacks: These are the clever ones that target specific applications with seemingly legitimate requests. HTTP floods (overwhelming a web server with GET or POST requests), slow loris attacks (opening connections very slowly to tie up server resources), and DNS query floods (bombarding DNS servers with requests) fall into this category.
How can PRTG help when I'm under attack?

While PRTG isn't a DDoS mitigation tool itself (it won't stop the attack for you), it's an essential part of your defense strategy. PRTG provides early detection through continuous monitoring of traffic patterns and can alert you when potential attack indicators are detected. It offers visibility into the effectiveness of your mitigation techniques and helps identify the type of attack through detailed traffic analysis. For complete protection, PRTG works best alongside dedicated DDoS protection services from ISPs or security service providers.

What should I be looking for to catch DDoS attacks early?

You can use PRTG to keep an eye on these key metrics:

  • Bandwidth usage (both overall and broken down by protocol)
  • Connection rates and states (especially for TCP connections)
  • Request rates to your web applications and APIs
  • DNS query volumes
  • Network latency and packet loss
  • Server resource usage (CPU, memory, connection tables)
  • Traffic distribution by source IP addresses
What is a sensor in PRTG?

In PRTG, “sensors” are the basic monitoring elements. One sensor usually monitors one measured value in your network, for example the traffic of a switch port, the CPU load of a server, or the free space on a disk drive. On average, you need about 5-10 sensors per device or one sensor per switch port.

We asked: would you recommend PRTG? Over 95% of our customers say yes!

Paessler conducted trials in over 600 IT departments worldwide to tune its network monitoring software closer to the needs of sysadmins. The result of the survey: over 95% of the participants would recommend PRTG – or already have.

recommendation

Still not convinced?

Love

More than 500,000 sysadmins love PRTG

Paessler PRTG is used by companies of all sizes. Sysadmins love PRTG because it makes their job a whole lot easier.

PRTG

Monitor your entire IT infrastructure

Bandwidth, servers, virtual environments, websites, VoIP services – PRTG keeps an eye on your entire network.

test

Try Paessler PRTG for free

Everyone has different monitoring needs. That’s why we let you try PRTG for free.

PRTG Logo

Start DDoS monitoring with PRTG and see how it can make your network more reliable and your job easier.

Free download
PRODUCT OVERVIEW

Products

  • Paessler PRTG
    Paessler PRTGMonitor your whole IT infrastructure
    • PRTG Network Monitor
    • PRTG Enterprise Monitor
    • PRTG Hosted Monitor
    • PRTG extensions
      Extensions for Paessler PRTGExtend your monitoring to a new level
  • Icon Features
    FeaturesExplore all monitoring features

Monitoring with PRTG

  • Network monitoring
  • Bandwidth monitoring
  • SNMP monitoring
  • Network mapping
  • Wi-Fi monitoring
  • Server monitoring
  • Network traffic analyzer
  • NetFlow monitoring
  • Syslog server

Useful Links

  • PRTG Manual
  • Knowledge Base
  • Customer Success Stories
  • About Paessler
  • Subscribe to newsletter
  • PRTG Support
  • PRTG Consulting
  • PRTG Feedback & Roadmap

Contact

Paessler GmbH
Thurn-und-Taxis-Str. 14, 
90411 Nuremberg 
Germany

info@paessler.com

+49 911 93775-0

  • Contact us
©2025 Paessler GmbHTerms & ConditionsPrivacy PolicyImprintReport VulnerabilityDownload & InstallSitemap
Home Home Home