Network Management
SolarWinds is detected as the source of a Denial of Service attack
This article provides information about why SolarWinds might be identified by security tools as the source of Denial of Service (DOS) attack.
First published date
Last published date
Overview
Product section
Resolution
SolarWinds is commonly identified as the source of a Denial of Service attack. This happens because SolarWinds polls information using ICMP, SNMP, and WMI. It collects information every 2 minutes by default. Another reason is that SolarWinds uses fast polling if it did not receive information from a monitored node or a node does not reply to a SolarWinds request.
For more information, see this thread:
https://thwack.solarwinds.com/thread/41933
Recommendation:
It is recommended to exempt SolarWinds from your security scan.
Please note that Thwack is a community space where users may post any content as a suggestion or recommendations to you for your internal use. The information set forth herein may come from third-party websites or customers. SolarWinds is not liable for any downtime or any issue that may occur if you perform the following suggestions on the link provided. Your organization should internally review and assess to what extent, if any, such custom scripts or recommendations will be incorporated into your environment.