so yeah all the info is in the DB
I think I will be able to do something about it and add the IP from event log to iptables, probably will need to run it from a crontab and block such IP for the whole system...
will post/update on the progress if anyone else would like to do similar system level blocking via IPtables rather than just have temporary ban. That IP seems to be coming from well known location for hackers, so I certainly don't need such on my system.
database_single=# select * from blacklist
database_single-# ;
idblacklist | ipaddr | ipmask | description | expiresat | blocktype
-------------+----------------+-----------------+--------------------------------------------------+-------------+-----------
113 | 195.154.42.164 | 255.255.255.255 | PBX: blocked for too many failed authentications | 13164470456 | 0
7 | 192.168.1.0 | 255.255.255.0 | Private Network | 13790548832 | 1
8 | 192.168.2.0 | 255.255.255.0 | Private Network | 13790548855 | 1
20 | 185.107.83.35 | 255.255.255.255 | weird ip, spanning alarms | 13792930470 | 0
(8 rows)
database_single=# select * from eventlog;
ideventlog | entrytype | source | eventid | timegenerated | params | tag
------------+-----------+----------------------------+---------+------------------------+---------------------------------------------------------------------------------+-----
904 | 4 | Event Notification Manager | 10025 | 2018-02-26 05:05:33+00 | {""} |
905 | 1 | SIP Server/Call Manager | 12290 | 2018-02-28 03:52:14+00 | {195.154.42.164,86400,"2018/02/28 22:52:14","Too many failed authentications!"} |
906 | 1 | SIP Server/Call Manager | 12292 | 2018-03-01 01:03:29+00 | {162.245.236.26,20} |
907 | 1 | SIP Server/Call Manager | 12292 | 2018-03-01 03:52:24+00 | {195.154.42.164,1001} |
908 | 1 | SIP Server/Call Manager | 12292 | 2018-03-01 04:10:15+00 | {195.154.42.164,1001} |
909 | 1 | SIP Server/Call Manager | 12292 | 2018-03-01 04:28:03+00 | {195.154.42.164,1001} |
910 | 1 | SIP Server/Call Manager | 12292 | 2018-03-01 04:46:02+00 | {195.154.42.164,1001} |
911 | 1 | SIP Server/Call Manager | 12292 | 2018-03-01 05:03:53+00 | {195.154.42.164,1001} |
912 | 1 | SIP Server/Call Manager | 12292 | 2018-03-01 05:22:03+00 | {195.154.42.164,1001} |
913 | 1 | SIP Server/Call Manager | 12292 | 2018-03-01 05:43:55+00 | {195.154.42.164,1001} |
914 | 1 | SIP Server/Call Manager | 12292 | 2018-03-01 06:00:54+00 | {195.154.42.164,1001} |
915 | 1 | SIP Server/Call Manager | 12292 | 2018-03-01 06:17:41+00 | {195.154.42.164,501} |
916 | 1 | SIP Server/Call Manager | 12292 | 2018-03-01 06:27:42+00 | {195.154.42.164,1001} |
917 | 1 | SIP Server/Call Manager | 12292 | 2018-03-01 06:51:02+00 | {195.154.42.164,1001} |
918 | 1 | SIP Server/Call Manager | 12292 | 2018-03-01 07:07:46+00 | {195.154.42.164,1001} |
919 | 1 | SIP Server/Call Manager | 12292 | 2018-03-01 07:27:41+00 | {195.154.42.164,501} |
920 | 1 | SIP Server/Call Manager | 12292 | 2018-03-01 07:37:31+00 | {195.154.42.164,501} |
921 | 1 | SIP Server/Call Manager | 12292 | 2018-03-01 07:47:29+00 | {195.154.42.164,1001} |
922 | 1 | SIP Server/Call Manager | 12292 | 2018-03-01 08:07:25+00 | {195.154.42.164,1001} |
923 | 1 | SIP Server/Call Manager | 12292 | 2018-03-01 08:43:27+00 | {195.154.42.164,501} |
924 | 1 | SIP Server/Call Manager | 12292 | 2018-03-01 08:53:28+00 | {195.154.42.164,1001} |
925 | 1 | SIP Server/Call Manager | 12292 | 2018-03-01 09:13:23+00 | {195.154.42.164,1001} |
926 | 1 | SIP Server/Call Manager | 12292 | 2018-03-01 09:36:25+00 | {195.154.42.164,501} |
927 | 1 | SIP Server/Call Manager | 12292 | 2018-03-01 09:46:22+00 | {195.154.42.164,19} |
928 | 1 | SIP Server/Call Manager | 12292 | 2018-03-01 09:49:42+00 | {195.154.42.164,1001} |
929 | 1 | SIP Server/Call Manager | 12292 | 2018-03-01 10:09:43+00 | {195.154.42.164,1001} |
930 | 1 | SIP Server/Call Manager | 12292 | 2018-03-01 10:36:10+00 | {195.154.42.164,501} |
931 | 1 | SIP Server/Call Manager | 12292 | 2018-03-01 10:46:03+00 | {195.154.42.164,1001} |
932 | 1 | SIP Server/Call Manager | 12292 | 2018-03-01 11:08:24+00 | {195.154.42.164,501} |
933 | 1 | SIP Server/Call Manager | 12292 | 2018-03-01 11:18:15+00 | {195.154.42.164,501} |
934 | 1 | SIP Server/Call Manager | 12292 | 2018-03-01 11:34:47+00 | {195.154.42.164,1001} |
935 | 1 | SIP Server/Call Manager | 12292 | 2018-03-01 11:54:58+00 | {195.154.42.164,1001} |
936 | 1 | SIP Server/Call Manager | 12292 | 2018-03-01 12:14:45+00 | {195.154.42.164,501} |
937 | 1 | SIP Server/Call Manager | 12292 | 2018-03-01 12:31:22+00 | {195.154.42.164,1001} |
938 | 1 | SIP Server/Call Manager | 12290 | 2018-03-01 13:20:56+00 | {195.154.42.164,86400,"2018/03/02 08:20:56","Too many failed authentications!"} |
(35 rows)
database_single=#