Hi,
I’ve been keeping an eye on the Top IPDB Attacker IPs list in cPFence and noticed that some IPs regularly appear as attackers. However, I’m not able to locate exactly which logs triggered that classification.
I’d like to understand what type of event was detected (login attempts, scans, SMTP abuse, etc.) so that I can report the logstamp or the related events with maximum detail for any given IP.
In fact, this week I made a mistake: one of the IPs listed there led me to file an abuse report against an Enhance server IP (orchd), simply because I couldn’t identify the log or the specific reason why it appeared in the Top IPDB Attacker IPs.
If anyone can point me to where these logs can be found — whether through the cPFence panel, via CLI, or in a specific directory on the server — I would really appreciate it.
Thank you!