Skip to content

Layer7 Dstat — Live Application-Layer Traffic

What is a Layer7 Dstat?

A Layer7 Dstat measures traffic at the application layer (OSI Layer 7): the HTTP/HTTPS requests per second (RPS) that reach the web server. It reflects request-based attacks such as HTTP floods and cache-bypass methods, and shows whether protection layers like a WAF, JS challenge (UAM), managed challenge (CAPTCHA) or rate limit are actually filtering the requests.

About

Layer7 Dstat vs Layer4 Dstat

A Layer7 Dstat is measured in requests per second and reflects application / CPU cost; a Layer4 Dstat is measured in bandwidth (Gbps) and packets per second (pps) and reflects raw network saturation. Layer 7 is defended at the edge with WAFs and challenges, while Layer 4 is mitigated upstream with scrubbing and capacity.

Related Live Dstat Examples (Layer 7)

Layer7 Dstat FAQ

What does a Layer7 Dstat measure?

Application-layer traffic: the HTTP/HTTPS requests per second (RPS) reaching the web server, plus how many passed, bypass protection or get blocked.

What is the difference between a Layer7 Dstat and a Layer4 Dstat?

A Layer7 Dstat tracks requests per second (application attacks); a Layer4 Dstat tracks bandwidth and packets (volumetric attacks). Layer 7 overwhelms the application, Layer 4 saturates the network.

Why does total request volume not tell the whole story?

Against a protected target, what matters is how many requests passed or bypass the protection versus blocked at the edge. A Layer7 Dstat shows that breakdown, which raw volume alone cannot.

Learn more