Forum Discussion
PeteWhite
Jan 18, 2020Employee
Should be pretty simple - look at /config/user_alert.conf but note that https://support.f5.com/csp/article/K14397 mentions that dosl7d cannot be used to trigger emails this way. However, you could probably quite easily use an iRule to create a specific syslog message when you see a specific violation.
See https://support.f5.com/csp/article/K3667 for how to setup email alerts
eg
when IN_DOSL7_ATTACK {
log local0.error "IP: $DOSL7_ATTACKER_IP Mitigation: $DOSL7_MITIGATION"
}