Forum Discussion
Attack type in ASM::violation_data always blank
Howdy.
With an iRule logging ASM events over HSL, we use ASM::violation_data on 10.2.4. the 5th field, attack type, is apparently ALWAYS blank.
If I just do a log local0. [ASM::violation_data] and spoof a directory traversal I can see...
Mar 5 10:58:57 local/tmm1 info tmm1[4923]: Rule hsl_logging_irule : VIOLATION_ATTACK_SIGNATURE_DETECTED 4316674533163547263 str_apache_class Informational 10.123.45.6 {} blocked
Any clues??
Thanks
Chris
2 Replies
- nathe
Cirrocumulus
Chris,
According to the wiki ASM::violation that's not quite how this command works. It has multiple, delimited, fields. Hopefully the wiki will give you a steer on capturing the violation type.
Hope this helps,
N
- Chris_Phillips
Nimbostratus
I'm just dumping it out to prove a point, I'm comfortable using the data list in a more formal way, I just need to know why it's always empty and if this can be addressed as I would, in line with the wiki expect a raft of useful description tags to be in that field, but clearly it's empty.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com