Howdy, Stranger!

It looks like you're new here. If you want to get involved, click one of these buttons!


Shells Virtual Desktop
BMail.ag - Secure Email Service
Server.net
CPLicense.net
VPS Server
Buy VPN
Vultr
VMs for AI
HostDare
ReliableSite White-Label Dedicated Hosting for Resellers
InterServer VPS
BMail.ag - Secure Email Service
Best VPN
High-Performance Bare Metal Server Solutions
Karvl.com
Server Mania Cloud Hosting
DataWagon Hosting
AlphaVPS Hosting
Evoxt.com
Clouvider
VPS Hosting with NVMe
Residential IPs in the US & 4G Mobile Proxies in EU & US with Unlimited Bandwidth
ReliableSite White-Label Dedicated Hosting for Resellers
Rabisu - Hosting Solutions
Shells Virtual Desktop
New on LowEndTalk? Please Register and read our Community Rules.

All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.

What kind of logging and analysis on logs do guys use for dealing with HTTP attacks?

rchurchrchurch Barred
edited March 2021 in General

After the problems covered in Problem with provider IP address I'd like to know what LETs use for dealing with such problems.

EDIT: It seems what I want is a WAF, and one spoken about here is mod_security. Are there any others I should consider? Which are the recommended ones?

My plan now is to save the logs into a database and analyze that with a script, and searches have revealed that rsyslog/syslog can log directly to a database, although I could also do that directly with a script that reads the logs directly.

So after loading the logs into the database, what kind of patterns are usually searched and how are they usually dealt with if they are considered hostile, besides the usual method of banning the IP address.

Sign In or Register to comment.