Virtual Server Is Under Attack

Comtrade.F5.BigIp.ASM.VirtualServer.IsUnderAttack.Monitor (UnitMonitor)

This monitor checks if the F5 LTM Virtual Server is under attack.

Knowledge Base article:

Summary

This monitor checks if the F5 LTM Virtual Server is under attack.

Configuration

The following configuration parameters are customizable:

Debug

When true, writes more information into event log. Default value is false.

Use Cache

If true, cache will be used, in order to minimize impact of monitoring on the F5 BIG-IP device. Default value is true.

Synchronization Time

Synchronization time in a 24-hour format. No default value is specified.

Timeout Seconds

Timeout in seconds. This value is used for setting timeout value to access the BIG-IP appliance. Default value is 270 seconds.

Update Interval in Seconds

Recurring scheduled interval in seconds used for running the workflow. Default value is 300 seconds.

Number Of Events To Fetch With Each Request

Number of events that will be fetched with each request to the BIG-IP. This parameter can be modified to minimize the performance impact on the F5 BIG-IP Device. Default value is 500 events.

Causes

Appication Security Module on the BIG-IP device has detected that this virtual server is under attack.

Resolutions

This alert will automatically be resolved once the attacks on the virtual server stop.

Element properties:

TargetComtrade.F5.BigIp.LTMVirtualServer
Parent MonitorSystem.Health.SecurityState
CategorySecurityHealth
EnabledFalse
Alert GenerateTrue
Alert SeverityMatchMonitorHealth
Alert PriorityNormal
Alert Auto ResolveTrue
Monitor TypeComtrade.F5.BigIp.ASM.Monitoring.2State.AlertIfAttackVirtualServer.UnitMonitorType
RemotableTrue
AccessibilityPublic
Alert Message
Virtual Server Is Under Attack
Local Traffic Virtual server {0}, configured to use {1} policy is under attack from {2} (UTC) on at least one device where it is active.
Attacks have been detected on following device(s):
{3}
RunAsDefault