waf_top_ips
Identify the most active attacking IPs by retrieving top sources with hit counts, geographic location, and last seen timestamp within a specified time window.
Instructions
Top attacking IPs with hit counts, geo info, and last seen timestamp. Use to identify most active sources.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| count | No | Number of top IPs to return (default 10) | |
| since | No | Time window for log search (e.g. '1h', '24h', '7d'). Default: 24h | 24h |