Wasfi_Bounni
Nov 21, 2019Cirrocumulus
Solved
Can I see the "failed login attemps" counter for a page defined as login page on the AWAF?
Hi;
Let's say I want to put the "default" brute-force protection in place for a page defined as a login page. Let's also say that I want to display a CAPTCHA after 3 failed login attempts from the same "username".
I am sure that the system keeps a counter of the failed login attempts associated with the same username in order to display the CAPTCHA.
My question is can this counter be seen somewhere as it increments?
Kindly
Wasfi
You can see it in the ASM request log for the failed attempt.
The ASM request log will list the username and the number of attempts.