logging suspicious behavior /ddos, failed login attempts etc

Suggest improvements and new features for Gargoyle.

Moderator: Moderators

Post Reply
razorpl
Posts: 23
Joined: Fri Mar 16, 2012 8:26 am

logging suspicious behavior /ddos, failed login attempts etc

Post by razorpl »

Hi there.
Is there possibility to log suspicious behaviour like ddos, or logging attempts successful/unsuccessful. and send it to desired email?

Draggeta
Posts: 1
Joined: Fri Jun 01, 2012 7:24 pm

Re: logging suspicious behavior /ddos, failed login attempts

Post by Draggeta »

I have to agree with this. The stock firmware of the WNDR3700 has a log and it is very handy to see if something strange is happened during the day, while also being able to send daily logs to my mail.

razorpl
Posts: 23
Joined: Fri Mar 16, 2012 8:26 am

Re: logging suspicious behavior /ddos, failed login attempts

Post by razorpl »

Dear founder of gargoyle project. WIll You consider adding this option?

sigwx
Posts: 70
Joined: Fri Oct 23, 2015 4:14 am

Re: logging suspicious behavior /ddos, failed login attempts

Post by sigwx »

Hello

Add another to the list of users that would appreciate having this feature.

Lantis
Moderator
Posts: 6753
Joined: Mon Jan 05, 2015 5:33 am
Location: Australia

Re: logging suspicious behavior /ddos, failed login attempts

Post by Lantis »

There is an email logging plugin.
And the system log already logs failed authentication and ssh attempts.

Is there any other functionality that you require?
http://lantisproject.com/downloads/gargoyle_ispyisail.php for the latest releases
Please be respectful when posting. I do this in my free time on a volunteer basis.

sigwx
Posts: 70
Joined: Fri Oct 23, 2015 4:14 am

Re: logging suspicious behavior /ddos, failed login attempts

Post by sigwx »

I think the idea is having a way to include
option log '1'

as part of /etc/config/firewall in the zone for the wan, so that any dropped/rejected attempt is logged as part of /var/log/messages

Post Reply