Abdessamad1
Nov 12, 2018Cirrostratus
ASM L7DOS snmp traps
Dear,
Do you know of any known issue about l7ddos snmp traps. For some reason they are not sent at all.
The log entry in /var/log/dosl7/dosl7d.log is well present, but no snmp trap is sent.
I checked the definition in the alertd config files and it looks like it is looking for a specific log entry in order to send the trap:
alert.conf
alert BIGIP_TS_TS_DOS_ATTACK_DETECTED_ERR {
snmptrap OID=".1.3.6.1.4.1.3375.2.4.0.91";
}
bigip_ts_error_maps.h
3 LOG_ERR 01310046 BIGIP_TS_TS_DOS_ATTACK_DETECTED_ERR "[SECEV] DoS attack: %s. HTTP classifier: %s, Operation mode: %s"
But the problem is that when testing a l7ddos, no log entry can be found in /var/log/asm, there are only logs in /var/log/dosl7/dosl7d.log
And it looks like the alertd does not process the later file (K14397)
My client is running version 11.5.4
Thanks in advance for your assistance.
Abdessamad