shieldlist-panel Free
Brute force against the Shieldlist console or API
- Category
panel- Threshold
5/10m, 15/1h- Ban policy
web- Parsers
-
shieldlist-refused
Why it is written this way
Somebody guessing at the console or the API: five refusals in ten
minutes, or fifteen in an hour, and the address is banned on the machine
that runs the controller. The agent there reads the controller's log:
log_inputs: [{path: /var/log/shieldlist/controller.log, category: shieldlist}]
The rule file View raw
# Somebody guessing at the console or the API: five refusals in ten # minutes, or fifteen in an hour, and the address is banned on the machine # that runs the controller. The agent there reads the controller's log: # log_inputs: [{path: /var/log/shieldlist/controller.log, category: shieldlist}] rule: shieldlist-panel description: Brute force against the Shieldlist console or API category: panel parsers: shieldlist-refused threshold: [5/10m, 15/1h] ban: web