-
Notifications
You must be signed in to change notification settings - Fork 164
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Add Postfix spam messages #830
Conversation
@kravietz can you please provide some tests / sample logs ? see https://doc.crowdsec.net/docs/next/scenarios/create#create-our-test |
@buixor Sure, here are just a few recent log entries matched by this rule:
|
Another question any reasonyou didn't incorporate it within the current postfix-logs parser under |
@LaurenceJJones No, I did it in a separate file exclusively to avoid messing up the existing parser but once you're happy with it it would absolutely make sense to keep them in one file. |
It has been now merged into the main |
Sample log for the third (SASL bruteforcing) rule:
|
@LaurenceJJones Does this need any further updates or change on my side? |
I will classify this PR as closed due to spam messages can be configured to user spam settings meaning the data can be non consistent. Feel free to reopen the PR if you do not agree with this classification and the IP address detect by this scenario is worth the rest of the community to use. |
Detect and block persistent spammers