Posted on 09/02/2022 16:49:55
Yeah
You can, kind of - I'll look into better logging. Have a bit of limitation due to the logging api that has been abstracted into hell and beyond, so it cannot be changed without 7 university degrees and a rewrite of all of DW... I f***ing hate developers. :-).
Anyways - when in monitoring/event viewer, you can see bans using the "Security/IpBanner" - some bans are easy - IP posted too many times. Others, like "Match on XYZ" is secret.
But if you change the event viewer to look at "Security/SqlInjection" you get a bit more information - like the one below:
In this example the querystring contained ?file=/**/cOnvert... etc.
BR Nicolai