Forum Discussion
Moustafa
Jun 09, 2020Nimbostratus
hi Samir ,
thanks for information . i tried the below I rule i think its working .
when CLIENT_ACCEPTED {
log local0. "Source IP address and Port is [IP::client_addr]:[TCP::client_port]"
log local0. "cloc [whereis [IP::client_addr] country]"
log local0. "Geo Client ([IP::client_addr]) detected"
}