Sérgio,
The current version of SmarterMail includes logging for the IDS brute force rules similar to what you are looking for in the Administrative logs. Look for entries like this:
00:00:27.103 [IP ADDRESS] SMTP Login failed: Invalid username (EMAIL ADDRESS) and password combination.
Brute force attempts increased to 6 of 25 in 600 minutes.
User brute force attempts increased to 1 of 50 in 10 minutes.
Next clean available at 10/12/2023 12:01:16 AM
The line starting with "Brute force attempts..." indicates the progress toward triggering a Brute Force by IP rule, while the "User brute force attempts..." indicates the progress toward triggering a Brute Force by Email rule.
The administrative logs will also include lines like the following when a rule is triggered:
0:01:32.308 [IpBruteForceDetector] [IP ADDRESS] Added to IDS block list for violating rule Type: Password Brute Force by IP, Description: Default Brute Force by IP rule
00:01:32.310 [IpBruteForceDetector] Added IP ADDRESS to IDS block list. Duration: 30000 seconds, Description: Default Brute Force by IP rule
Due to the order of handling, these lines should be shortly before an entry like the first I provided which indicates the count has been reached.
Andrew Barker
Software Developer
SmarterTools Inc.
www.smartertools.com