DDOS attack mitigated

Hello everyone, my nodeJS app was recently attacked by DDOS, and luckily cloudflare has stopped this attack.

after looking at the user IP I was able to pinpoint the culprit and took a look at the user's activity.. but I could not deduce anything, he looks clean. as if they did not do anything.

I need your help educating me how I can make respond properly to this incident. they are a legit paying customer and it would not be fare to ban them after they've payed...
can someone provide me with proper tips to respond to this?
Was this page helpful?