Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

A couple feature requests #90

Open
MadCowChicken opened this issue Mar 27, 2022 · 3 comments
Open

A couple feature requests #90

MadCowChicken opened this issue Mar 27, 2022 · 3 comments
Assignees
Labels
enhancement thats a planned enhancement

Comments

@MadCowChicken
Copy link

MadCowChicken commented Mar 27, 2022

Part 1

Feature request: Global config file settings for:

  • LockTime
  • EventAge
  • TriggerCount
  • PermaBanCount

Then for each type of event (RDP, SSH, FTP etc...) the same four XML elements can be present, and global settings used if they are empty.

Part 2

Also, how does the EvlWatcher Windows service work? Does it pull all Windows Security events within EventAge every time it polls the Windows Security Event Log? Or does it only do that when the service starts, and after that it only pulls events that have been created since the last polling, aggregating across multiple pollings, and dropping events if they are older than EventAge? I ask because if someone set EventAge to 10 hours expecting it to do the latter, they would probably use a different value like 10 minutes if they knew it did the former. I recommend explaining clearly how the service works in the config file.

@devnulli devnulli added question thats a question feature request an idea that could improve the software labels Mar 29, 2022
@devnulli devnulli self-assigned this Mar 29, 2022
devnulli added a commit that referenced this issue Mar 29, 2022
@devnulli
Copy link
Owner

devnulli commented Mar 29, 2022

ad Part 2: changed the comment in the config.xml so that it now states:

image

@devnulli
Copy link
Owner

devnulli commented Mar 29, 2022

ad Part 1:

that will be implemented, as it is also how fail2ban does it (iirc)

@devnulli devnulli added enhancement thats a planned enhancement and removed question thats a question feature request an idea that could improve the software labels Mar 29, 2022
@devnulli
Copy link
Owner

reopened for part 1

@devnulli devnulli reopened this Apr 14, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement thats a planned enhancement
Projects
None yet
Development

No branches or pull requests

2 participants