Hi, everyone:
I've found some interesting settings in the nginx plugins, which is called "honeypot". If any ip had visited this location, the source ip will be added to the nginx_block_list, and that's a great feature.
But after some ips get blocked, there will be no access/error log in the webgui. How can I get the info about what the bad guys did? e.g. hostname, url, timestamp, action, etc.
I've found some interesting settings in the nginx plugins, which is called "honeypot". If any ip had visited this location, the source ip will be added to the nginx_block_list, and that's a great feature.
But after some ips get blocked, there will be no access/error log in the webgui. How can I get the info about what the bad guys did? e.g. hostname, url, timestamp, action, etc.
"