igor_
Sep 04, 2024Cirrus
F5 Malicious Source IP Address Alert
Hi all,
Recently we had F5 detect an ongoing malicious attack which we saw on the panel Security > Event Logs > Application > Requests.
Is there a way to configure F5 to send an alert email to our NOC team in real time whenever this happens?
BR,
The malicious IP means that this ip has done more than 10 violations.
Malicious Source IP Addresses (f5.com)
You can make and schedule ASM/AWAF default or custom report and send it by email:
You can see also session tracking to block ip addresses that generate too many violations and then configure the report for this violation or look into your SIEM for the violation:
Preventing Session Hijacking and Tracking User Sessions (f5.com)