Re: Declude Hijack Alert
Question asked by Hemen Shah - January 2, 2016 at 6:59 AM
I am using declude setup with hijack and all of sudden alert mails have stopped, i do see that declude is running fine based on logs but when some user is crossing the hijack threshold of 50/100 mails then it not throwing alert at the same time SM is doing the job based on events configured.
any advise here..

3 Replies

Reply to Thread
Hemen Shah Replied
January 5, 2016 at 1:31 PM
Anyone using hijack here can advise !!
Martin Schaible Replied
January 10, 2016 at 7:33 AM
I'm quite familiary with declude and hijack. Could you please post, how your configuration file for hijack looks like?
Martin Schaible Replied
January 11, 2016 at 9:45 AM
Your configuration is okay.
Declude sends you an E-Mail if the second threshold was reached. Hijack moves now all sending mails from the affected IP-Address to the folder spam\hold2. To release the IP-Address, the service of Declude needs to be restarted, which is a bit boring.
So you get one E-Mail per captured IP-Address. To be honest, i never had the case, that several IP-Addresses where be captured on one day. Therefore i can't confirm, that you get a warning for the following attacks.

Hope this helps.

Reply to Thread