Forum Discussion

Abdessamad1's avatar
Abdessamad1
Icon for Cirrostratus rankCirrostratus
Nov 12, 2018

ASM L7DOS snmp traps

Dear,

Do you know of any known issue about l7ddos snmp traps. For some reason they are not sent at all.

The log entry in /var/log/dosl7/dosl7d.log is well present, but no snmp trap is sent.

I checked the definition in the alertd config files and it looks like it is looking for a specific log entry in order to send the trap:

alert.conf

alert BIGIP_TS_TS_DOS_ATTACK_DETECTED_ERR {
        snmptrap OID=".1.3.6.1.4.1.3375.2.4.0.91";
}

bigip_ts_error_maps.h

3 LOG_ERR       01310046 BIGIP_TS_TS_DOS_ATTACK_DETECTED_ERR "[SECEV] DoS attack: %s. HTTP classifier: %s, Operation mode: %s"

But the problem is that when testing a l7ddos, no log entry can be found in /var/log/asm, there are only logs in /var/log/dosl7/dosl7d.log

And it looks like the alertd does not process the later file (K14397)

My client is running version 11.5.4

Thanks in advance for your assistance.

Abdessamad

No RepliesBe the first to reply