---
title: 'lfd:tracking:distributedattack'
url: 'https://docs.danami.com/juggernaut/command-line-interface/lfd/lfd-tracking-distributedattack'
markdown: 'https://docs.danami.com/juggernaut/command-line-interface/lfd/lfd-tracking-distributedattack.md'
date: '2026-10-07'
description: 'Configure the tracking of login failures from distributed IP addresses to a specific application account. juggernaut --task=lfd:tracking:distributedattack Option Value Default Description --LF_DISTATTACK <1|0> 0 Enable the tracking of login failures from distributed IP addresses t…'
taxonomy:
  category:
    - docs
  tag:
    - tracking
---

[](#)  [ Basics ](https://docs.danami.com/juggernaut/)     [ Command Line Interface ](https://docs.danami.com/juggernaut/command-line-interface)      Lfd       lfd:tracking:distributedattack    

# lfd:tracking:distributedattack

Configure the tracking of login failures from distributed IP addresses to a specific application account.

```
juggernaut --task=lfd:tracking:distributedattack
```

| Option | Value | Default | Description |
|---|---|---|---|
| `--LF_DISTATTACK` | <1\|0> | 0 | Enable the tracking of login failures from distributed IP addresses to a specific application account. If the number of failures matches the application trigger then all the IP addresses involved in the attack will be blocked. Tracking applies to LF\_SSHD, LF\_FTPD, LF\_SMTPAUTH, LF\_POP3D, LF\_IMAPD, LF\_HTACCESS. |
| `--LF_DISTATTACK_UNIQ` |  | 2 | The minimum number of unique IP addresses that trigger LF\_DISTATTACK. |
| `--LF_DIST_INTERVAL` |  | 300 | The interval in seconds during which a distributed FTP is measured. |
| `--LF_DIST_ACTION` | <string> |  | The path to a script that will run when a distributed FTP login event is triggered. |
| `--LF_DISTFTP` |  | 0 | Keep track of successful FTP logins. If the number of successful logins to an individual account is at least LF\_DISTFTP in LF\_INTERVAL from at least LF\_DISTFTP\_UNIQ IP addresses then all the IP addresses will be blocked. To disable this option set to 0. |
| `--LF_DISTFTP_UNIQ` |  | 3 | The minimum number of unique IP addresses that trigger LF\_DISTFTP. LF\_DISTFTP\_UNIQ must be less than or equal to LF\_DISTFTP for this to function properly. |
| `--LF_DISTFTP_PERM` |  | 1 | Enable permanent or temporary blocking (1 = Permanent or any value greater than 1 equal to the number of seconds to temporarily block for). |
| `--LF_DISTSMTP` |  | 0 | Keep track of successful SMTP logins (Postfix only). If the number of successful logins to an individual account is at least LF\_DISTSMTP in LF\_DIST\_INTERVAL from at least LF\_DISTSMTP\_UNIQ IP addresses, then all the IP addresses will be blocked. To disable this option set to 0. This option can help mitigate the common SMTP account compromise attacks that use a distributed network of zombies to send spam. A sensible setting for this might be 5, depending on how many different IP addresses you expect to an individual SMTP account within LF\_DIST\_INTERVAL. |
| `--LF_DISTSMTP_UNIQ` |  | 3 | The minimum number of unique IP addresses that trigger LF\_DISTSMTP. LF\_DISTSMTP\_UNIQ must be less than or equal to LF\_DISTSMTP for this to function properly. |
| `--LF_DISTSMTP_PERM` |  | 1 | Enable permanent or temporary blocking (1 = Permanent or any value greater than 1 equal to the number of seconds to temporarily block for). |
| `--default` | <yes> |  | Reset all settings to their default values. |
| `--default_option` | <option> |  | Reset a specific setting to its default value. |
| `--restart` | <yes> |  | Restart the service after saving settings. |

## Examples

```
// enable LF_DISTATTACK tracking
juggernaut --task=lfd:tracking:distributedattack --LF_DISTATTACK=1 --restart=yes

// reset LF_DISTATTACK_UNIQ back to default
juggernaut --task=lfd:tracking:distributedattack --default_option=LF_DISTATTACK_UNIQ --restart=yes

// reset all settings back to default
juggernaut --task=lfd:tracking:distributedattack --default=yes --restart=yes

// detect a compromised mailbox used by a spam botnet: 5 SMTP logins from 3+ different IPs in 30 minutes
juggernaut --task=lfd:tracking:distributedattack --LF_DISTSMTP=5 --LF_DISTSMTP_UNIQ=3 --LF_DIST_INTERVAL=1800 --restart=yes
```

## Related Pages

- [Process Tracking](https://docs.danami.com/juggernaut/user-guide/process-tracking "Process Tracking")
- [Login Tracking](https://docs.danami.com/juggernaut/user-guide/login-tracking "Login Tracking")
- [Tracking Settings](https://docs.danami.com/juggernaut/settings/login-failure-daemon/tracking-settings "Tracking Settings")

 [ ](https://docs.danami.com/juggernaut/command-line-interface/lfd/lfd-tracking-connection) [](https://docs.danami.com/juggernaut/command-line-interface/lfd/lfd-tracking-login)

---

## Navigation

- Previous: [lfd:tracking:connection](https://docs.danami.com/juggernaut/command-line-interface/lfd/lfd-tracking-connection.md)
- Next: [lfd:tracking:login](https://docs.danami.com/juggernaut/command-line-interface/lfd/lfd-tracking-login.md)
