Global Blacklist IP Event Source

Purpose

Triggers the addition of an IP address to the global IP blacklist via the Global Blacklist IP Event Destination (for details on the process, see Global IP Blacklisting).

When used with another event destination, triggers an alert when there’s a request to put an IP address onto the global IP blacklist.

Global IP blacklisting allows temporarily blocking of all traffic for specific IP addresses or specific ranges of IP addresses. This event and Global Blacklist IP Added Event Source can be configured to trigger the addition of IP addresses to the global IP blacklist. For more information, see Global IP Blacklisting.

For more information regarding adding and editing Event Sources, see Editing Event Sources.

Attributes

Attribute Meaning

min timeout

Minimum timeout used when an entry is made to the global IP blacklist. This may overwrite the default setting made for the Blacklist IP Event Destination.

max timeout

Maximum timeout used when an entry is made to the global IP blacklist. This may overwrite the default setting made for the Blacklist IP Event Destination.

min ip4 netmask

Determines the netmask used when blacklisting IPv4 address ranges. For details, see Global IP Blacklisting and Specifying IP Addresses.

min ip6 netmask

Determines the netmask used when blacklisting IPv6 address ranges. For details, see Global IP Blacklisting and Specifying IP Addresses .

msg prefix

Here you can enter some text, which is added to the beginning of the issued alert (only used when the Global Blacklist IP Event Source is used in combination with another event destination than the Global Blacklist IP Event Destination).

The default text is "the following ip range is blacklisted:".