Work out whether a Fast Flood alert fires — and exactly how many seconds it takes — from the configured high severity threshold and the observed volume of attack traffic.
A high severity threshold of 100 Gbps means the destination must receive 6,000 Gb within the 60 second window before the threshold is considered breached.
At an attack traffic volume of 200 Gbps, that same 6,000 Gb arrives after just 30 s.
Because 30 s falls inside the 60 second window, Fast Flood fires at 30 s instead of waiting for the configured severity duration.
How the trigger time moves as the attack traffic volume varies around 200 Gbps, with the severity threshold held at 100 Gbps.
| Attack Traffic Volume | Δ | Trigger Time | Margin in Window | Fast Flood |
|---|
With Fast Flood enabled, Sightline raises an alert the moment the high severity threshold is breached inside a 60 second window — it does not wait out the configured severity duration.
The threshold is a rate, so the equivalent volume for the window is threshold × 60. Traffic accumulates at the attack rate until it reaches that volume.
Severity threshold 100 Gbps, attack traffic 200 Gbps. The window's threshold volume is 6,000 Gb; at 200 Gbps that arrives after 30 seconds, so Fast Flood triggers at 30 s.
If the threshold is not breached within 60 seconds, Fast Flood does not apply — the alert instead raises normally once the configured severity duration elapses.