I have a problem involving a shared server hosting many hidden services.
One of the hidden services is being attacked and this is causing the tor
daemon to use 100% CPU. I am quite sure the attack is just a DDOS flood.

What I can't seem to figure out is how to isolate which hidden service
is being attacked so I can disable it. I have tried enabling the info
log but it doesn't seem to contain the information I need. The debug log
is a quagmire, and I don't know what to look for.

Please tell me what to search for in the debug log.

