Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Possibility to show information in email which rule has blocked #999

Open
przemeksw opened this issue Jan 8, 2024 · 5 comments
Open

Possibility to show information in email which rule has blocked #999

przemeksw opened this issue Jan 8, 2024 · 5 comments

Comments

@przemeksw
Copy link

Is it possible to add information to an email message which rule worked for a given ddos block, including, for example, the configuration settings in brackets?

threshold_tcp_mbps = 90000
threshold_udp_mbps = 7500
threshold_icmp_mbps = 1000

threshold_tcp_pps = 58000
threshold_udp_pps = 20000
threshold_icmp_pps = 2000

Thanks

@DenisKlimek
Copy link

Maybe this could be archived by adding this information as the 5th argument value?

@pavel-odintsov
Copy link
Owner

pavel-odintsov commented Jan 31, 2024 via email

@przemeksw
Copy link
Author

Can't you just add this functionality to the community version?
This would make it easier to adjust the thresholds for individual configuration values.
All you need is information about which setting caught a given attack - nothing more

@pavel-odintsov
Copy link
Owner

I just marked it as feature request. Somebody from team or community may pick it up if they have spare cycles.

@przemeksw
Copy link
Author

Cool thanks !!!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

3 participants