# crowdsec

**URL:** https://discourse.crowdsec.net/c/crowdsec/5.md

[Latest](https://discourse.crowdsec.net/latest.md) · [Categories](https://discourse.crowdsec.net/categories.md)

---

## [Crowdsec on OPNsense and weird behaviour with notification-http process](https://discourse.crowdsec.net/t/crowdsec-on-opnsense-and-weird-behaviour-with-notification-http-process/2033)

<div class="topic-metadata">

**Author:** [@Finance6104](https://discourse.crowdsec.net/u/Finance6104)\
**Replies:** 4\
**Last updated:** [September 24, 2026, 6:35am UTC](https://discourse.crowdsec.net/t/crowdsec-on-opnsense-and-weird-behaviour-with-notification-http-process/2033 "2026-09-24T06:35:19Z")

</div>

I don’t know if this is a result of my misconfiguration or something else, but I found a behaviour that is really weird. I have a multi-server setup. My router (OPNsense box) is running as LAPI and other servers are run…

---

## [IPs fllagged as malicious in crowdsec still hitting my VPS. What can be the issue?](https://discourse.crowdsec.net/t/ips-fllagged-as-malicious-in-crowdsec-still-hitting-my-vps-what-can-be-the-issue/2930)

<div class="topic-metadata">

**Author:** [@bosunjohnson](https://discourse.crowdsec.net/u/bosunjohnson)\
**Replies:** 0\
**Last updated:** [September 21, 2026, 12:11pm UTC](https://discourse.crowdsec.net/t/ips-fllagged-as-malicious-in-crowdsec-still-hitting-my-vps-what-can-be-the-issue/2930 "2026-09-21T12:11:10Z")

</div>

I am sharing this as an example. I am still struggling to know how crowdsec works. I have some VPS with fail2ban but I just decided to include crowdsec a few days ago. I see IPs like this trying to brute force and acces…

---

## [Crowdsec decision expiration](https://discourse.crowdsec.net/t/crowdsec-decision-expiration/2920)

<div class="topic-metadata">

**Author:** [@Emmanuel](https://discourse.crowdsec.net/u/Emmanuel)\
**Replies:** 0\
**Last updated:** [August 26, 2026, 1:04pm UTC](https://discourse.crowdsec.net/t/crowdsec-decision-expiration/2920 "2026-08-26T13:04:22Z")

</div>

I have a crowdsec setup with a central server: Log Centralization | CrowdSec (a similar setup to this) The central server receives those logs and writes them into files. The Security Engine then analyzes those logs on…

---

## [Feature request - High Availability Support](https://discourse.crowdsec.net/t/feature-request-high-availability-support/2919)

<div class="topic-metadata">

**Author:** [@j0nny55555](https://discourse.crowdsec.net/u/j0nny55555)\
**Replies:** 0\
**Last updated:** [August 6, 2026, 6:13pm UTC](https://discourse.crowdsec.net/t/feature-request-high-availability-support/2919 "2026-08-06T18:13:31Z")

</div>

While the free option with one Engine is great, it would be amazing if we could use that (free one Engine) in an HA format. In this we would still be sending the same amount/group of parser/blocker/appsec agent data, bu…

---

## [Question about Postoverflow rules](https://discourse.crowdsec.net/t/question-about-postoverflow-rules/2918)

<div class="topic-metadata">

**Author:** [@rbaino](https://discourse.crowdsec.net/u/rbaino)\
**Replies:** 0\
**Last updated:** [July 9, 2026, 6:03am UTC](https://discourse.crowdsec.net/t/question-about-postoverflow-rules/2918 "2026-07-09T06:03:49Z")

</div>

Hi everyone, I struggle a bit with using Postoverflow rules. For a Nextcloud instance I am testing CrowdSec + AppSec with, although having the Nextcloud Whitelist ruleset installed, I still need to whiteliste a few thin…

---

## [Line 0/1 is missing evt.StrTime](https://discourse.crowdsec.net/t/line-0-1-is-missing-evt-strtime/2916)

<div class="topic-metadata">

**Author:** [@Thomas](https://discourse.crowdsec.net/u/Thomas)\
**Replies:** 0\
**Last updated:** [July 5, 2026, 3:17pm UTC](https://discourse.crowdsec.net/t/line-0-1-is-missing-evt-strtime/2916 "2026-07-05T15:17:03Z")

</div>

how to get ride of this line ? I’m on a debian 12 with CrowdSec version: v1.7.8-debian-pragmatic-amd64-63227459 Codename: alphaga BuildDate: 2026-05-11\_12:32:51 GoVersion: 1.26.2 Platform: linux libre2: C++ I spend…

---

## [CrowdSec Parser for Stalwart Logs](https://discourse.crowdsec.net/t/crowdsec-parser-for-stalwart-logs/2800)

<div class="topic-metadata">

**Author:** [@Mic2026](https://discourse.crowdsec.net/u/Mic2026)\
**Replies:** 19\
**Last updated:** [July 3, 2026, 6:12am UTC](https://discourse.crowdsec.net/t/crowdsec-parser-for-stalwart-logs/2800 "2026-07-03T06:12:23Z")

</div>

2.687 Hello CrowdSec Community, I’ve been using CrowdSec as an extension in the reverse proxy Caddy for quite some time, but I’m new to the community. Everything is running in a Docker Compose instance with its own …

---

## [Using Wordfence IP blockings (Wordpress WAF) for Crowdsec decisions](https://discourse.crowdsec.net/t/using-wordfence-ip-blockings-wordpress-waf-for-crowdsec-decisions/1921)

<div class="topic-metadata">

**Author:** [@Cyrille37](https://discourse.crowdsec.net/u/Cyrille37)\
**Replies:** 2\
**Last updated:** [June 17, 2026, 5:38am UTC](https://discourse.crowdsec.net/t/using-wordfence-ip-blockings-wordpress-waf-for-crowdsec-decisions/1921 "2026-06-17T05:38:37Z")

</div>

Hi, Wordfence is a great Wordpress WAF with many options for blocking IP on some unwanted behaviors. I did not find any thing on Internet about Crowdsec scenario using Wordfence blockings to take decision. I would like…

---

## [Decision not listed](https://discourse.crowdsec.net/t/decision-not-listed/1943)

<div class="topic-metadata">

**Author:** [@Tammes](https://discourse.crowdsec.net/u/Tammes)\
**Replies:** 12\
**Last updated:** [June 5, 2026, 12:42pm UTC](https://discourse.crowdsec.net/t/decision-not-listed/1943 "2026-06-05T12:42:14Z")

</div>

Hello, I have set up crowdsec 1.6.2 as multiserver setup on debian servers and installed the crowdsecurity/linux collection (which includes sshd) and the iptables firewall bouncer. When I try to ssh into a non existent …

---

## [TLS handshake timeout to https://api.crowdsec.net/](https://discourse.crowdsec.net/t/tls-handshake-timeout-to-https-api-crowdsec-net/2874)

<div class="topic-metadata">

**Author:** [@pedrobuffon](https://discourse.crowdsec.net/u/pedrobuffon)\
**Replies:** 1\
**Last updated:** [May 29, 2026, 4:37pm UTC](https://discourse.crowdsec.net/t/tls-handshake-timeout-to-https-api-crowdsec-net/2874 "2026-05-29T16:37:07Z")

</div>

i had to recreate my docker volumes, when crowdsec docker was creating the files i notice some weird behavior when it came to connecting to the https://api.crowdsec.net/, online\_api\_credentials.yaml was not being auto fi…

---

## [Best way to disable crowdsec for specific domain?](https://discourse.crowdsec.net/t/best-way-to-disable-crowdsec-for-specific-domain/2817)

<div class="topic-metadata">

**Author:** [@lexuzieel](https://discourse.crowdsec.net/u/lexuzieel)\
**Replies:** 0\
**Last updated:** [May 26, 2026, 1:59am UTC](https://discourse.crowdsec.net/t/best-way-to-disable-crowdsec-for-specific-domain/2817 "2026-05-26T01:59:02Z")

</div>

I have Crowdsec setup with Caddy and I am considering being able to enable/disable it for particular hosts (similar to how you can disable WAF in Cloudflare). I have stumbled upon this: Allowlisting and Rule Overrides | …

---

## [Improved exim parser](https://discourse.crowdsec.net/t/improved-exim-parser/2807)

<div class="topic-metadata">

**Author:** [@matthys70](https://discourse.crowdsec.net/u/matthys70)\
**Replies:** 0\
**Last updated:** [May 10, 2026, 12:43pm UTC](https://discourse.crowdsec.net/t/improved-exim-parser/2807 "2026-05-10T12:43:13Z")

</div>

I just noticed my exim parser at /etc/crowdsec/parsers/s01-parse/exim-logs.yaml was not working well. Even if it was parsing a very default exim4 mainlog file. I just want to share my current modified one (exim-logs.yam…

---

## [Running crowdsec as non-root user in Docker?](https://discourse.crowdsec.net/t/running-crowdsec-as-non-root-user-in-docker/2021)

<div class="topic-metadata">

**Author:** [@verybadsoldier](https://discourse.crowdsec.net/u/verybadsoldier)\
**Replies:** 5\
**Last updated:** [April 30, 2026, 10:05pm UTC](https://discourse.crowdsec.net/t/running-crowdsec-as-non-root-user-in-docker/2021 "2026-04-30T22:05:53Z")

</div>

Hi everyone, I am new to crowdsec and I have set up crowdsec using the Docker container from here in my home lab: https://hub.docker.com/r/crowdsecurity/crowdsec The container seems to running as root by default. Is i…

---

## [CrowdSec Appsec doesn't process JSON/XML](https://discourse.crowdsec.net/t/crowdsec-appsec-doesnt-process-json-xml/2787)

<div class="topic-metadata">

**Author:** [@oleksandr.yashchenko](https://discourse.crowdsec.net/u/oleksandr.yashchenko)\
**Replies:** 3\
**Last updated:** [April 22, 2026, 4:28pm UTC](https://discourse.crowdsec.net/t/crowdsec-appsec-doesnt-process-json-xml/2787 "2026-04-22T16:28:53Z")

</div>

Dear Community, During the migration to Crowdsec AppSec engine, we’ve noticed that JSON/XML request body headers aren’t processed automatically. It used to work for NGINX + ModSec + CRS stack. Environment: CrowdSec …

---

## [Haproxy spoa bouncer latency](https://discourse.crowdsec.net/t/haproxy-spoa-bouncer-latency/2799)

<div class="topic-metadata">

**Author:** [@jschaeff](https://discourse.crowdsec.net/u/jschaeff)\
**Replies:** 2\
**Last updated:** [April 16, 2026, 10:44am UTC](https://discourse.crowdsec.net/t/haproxy-spoa-bouncer-latency/2799 "2026-04-16T10:44:05Z")

</div>

Hello, I’m setting up the haproxy bouncer and it works great. We noticed that it adds a 500ms latency for all requests, and I could not find how to minimize it. First question : is such a latency expected ? If not wha…

---

## [Blocklist Integration with Check Point Firewall](https://discourse.crowdsec.net/t/blocklist-integration-with-check-point-firewall/2723)

<div class="topic-metadata">

**Author:** [@boombies](https://discourse.crowdsec.net/u/boombies)\
**Replies:** 9\
**Last updated:** [March 26, 2026, 7:07pm UTC](https://discourse.crowdsec.net/t/blocklist-integration-with-check-point-firewall/2723 "2026-03-26T19:07:20Z")

</div>

Has anyone successfully used the CrowdSec blocklist integration with a Check Point firewall IOC feed? Checkpoint | CrowdSec The documentation is pretty straight forward but it fails to pull the IOC feed. When putting th…

---

## [CrowdSec Appsec produces plenty of errors in OpenResty logs under high traffic](https://discourse.crowdsec.net/t/crowdsec-appsec-produces-plenty-of-errors-in-openresty-logs-under-high-traffic/2790)

<div class="topic-metadata">

**Author:** [@oleksandr.yashchenko](https://discourse.crowdsec.net/u/oleksandr.yashchenko)\
**Replies:** 1\
**Last updated:** [March 20, 2026, 4:46pm UTC](https://discourse.crowdsec.net/t/crowdsec-appsec-produces-plenty-of-errors-in-openresty-logs-under-high-traffic/2790 "2026-03-20T16:46:39Z")

</div>

Dear Community, Environment OS: Oracle Linux 9 OpenResty: v1.29.2.1 (ngx\_lua-0.10.29R2, lua-resty-http v0.12) CrowdSec: v1.7.6-rpm-pragmatic-amd64-eacc8192 CrowdSec OpenResty Bouncer: v1.1.1 AppSec: enabled, crowdsecu…

---

## [PostOverflow whitelists ONLY for specific scenarios](https://discourse.crowdsec.net/t/postoverflow-whitelists-only-for-specific-scenarios/2517)

<div class="topic-metadata">

**Author:** [@DuvelCorp](https://discourse.crowdsec.net/u/DuvelCorp)\
**Replies:** 2\
**Last updated:** [March 17, 2026, 8:34pm UTC](https://discourse.crowdsec.net/t/postoverflow-whitelists-only-for-specific-scenarios/2517 "2026-03-17T20:34:52Z")

</div>

Hi Basically I have this to whitelist some ASN of my country name: xxx/ASN-whitelist description: "Whitelist Trusted Belgian ASNs" #debug: true whitelist: reason: "xxx Whitelisted Belgian ASN" expression: - evt…

---

## [Can't start crowdsec in rootless podman](https://discourse.crowdsec.net/t/cant-start-crowdsec-in-rootless-podman/2788)

<div class="topic-metadata">

**Author:** [@Damncold](https://discourse.crowdsec.net/u/Damncold)\
**Replies:** 2\
**Last updated:** [March 15, 2026, 8:53pm UTC](https://discourse.crowdsec.net/t/cant-start-crowdsec-in-rootless-podman/2788 "2026-03-15T20:53:03Z")

</div>

Hi, im trying to get crowdsec running in rootless podman. But i get the following error: crowdsec-pangolin\[243452\]: ln: /var/lib/crowdsec/data/GeoLite2-ASN.mmdb: Permission denied I think the permissions are correct…

---

## [Whitelist ban by appsec](https://discourse.crowdsec.net/t/whitelist-ban-by-appsec/2785)

<div class="topic-metadata">

**Author:** [@soif-deconnaissance](https://discourse.crowdsec.net/u/soif-deconnaissance)\
**Replies:** 2\
**Last updated:** [March 13, 2026, 11:20am UTC](https://discourse.crowdsec.net/t/whitelist-ban-by-appsec/2785 "2026-03-13T11:20:43Z")

</div>

Hello everyone, I am encountering the following error with my GitLab server, which is behind NPMplus by Zoey2936 : 2026/03/10 15:12:09 \[alert\] 623#623: \*3881 \[lua\] crowdsec.lua:783: Allow(): \[Crowdsec\] denied '192.168.…

---

## [AppSec on VPS which do TLS passthrough to local machine behind CGNAT](https://discourse.crowdsec.net/t/appsec-on-vps-which-do-tls-passthrough-to-local-machine-behind-cgnat/2779)

<div class="topic-metadata">

**Author:** [@thingandstuff889](https://discourse.crowdsec.net/u/thingandstuff889)\
**Replies:** 4\
**Last updated:** [March 5, 2026, 10:20am UTC](https://discourse.crowdsec.net/t/appsec-on-vps-which-do-tls-passthrough-to-local-machine-behind-cgnat/2779 "2026-03-05T10:20:08Z")

</div>

Hi, First off thanks for making this wonderful piece of software. I have a specific setup like this: Client ⇒ VPS (Caddy L4 TLS passthrough) ⇒ (Wireguard) ⇒ Local machine (another Caddy do TLS termination) Currently I…

---

## [Appsec not working?](https://discourse.crowdsec.net/t/appsec-not-working/2778)

<div class="topic-metadata">

**Author:** [@urbaman](https://discourse.crowdsec.net/u/urbaman)\
**Replies:** 2\
**Last updated:** [March 3, 2026, 11:46am UTC](https://discourse.crowdsec.net/t/appsec-not-working/2778 "2026-03-03T11:46:00Z")

</div>

Hi, I’m trying to see if Appsec is working or not (cannot see any alerts triggered by appsec). sudo cscli appsec-configs list ────────────────────────────────────────────────────────────────────────────────────────────…

---

## [I am constantly being banned from my server](https://discourse.crowdsec.net/t/i-am-constantly-being-banned-from-my-server/1318)

<div class="topic-metadata">

**Author:** [@notban](https://discourse.crowdsec.net/u/notban)\
**Replies:** 4\
**Last updated:** [February 28, 2026, 11:31am UTC](https://discourse.crowdsec.net/t/i-am-constantly-being-banned-from-my-server/1318 "2026-02-28T11:31:49Z")

</div>

CrowdSec runs in the stack (Docker). Although I added my IP to the exception, I get banned regularly - at least 1x a day. It always depends on how often I use other Docker services like Seafile and how often I access m…

---

## [\[SQLITE\_CANTOPEN\] Unable to open the database file (unable to open database file)](https://discourse.crowdsec.net/t/sqlite-cantopen-unable-to-open-the-database-file-unable-to-open-database-file/1393)

<div class="topic-metadata">

**Author:** [@Dmitry](https://discourse.crowdsec.net/u/Dmitry)\
**Replies:** 6\
**Last updated:** [February 28, 2026, 7:14am UTC](https://discourse.crowdsec.net/t/sqlite-cantopen-unable-to-open-the-database-file-unable-to-open-database-file/1393 "2026-02-28T07:14:17Z")

</div>

Hello. I installed the dashboard and the installation was successful. However, I get this message: “\[SQLITE\_CANTOPEN\] Unable to open the database file (unable to open database file)” when I try to view the data. Cro…

---

## [Crowdsec and multiple public IPs](https://discourse.crowdsec.net/t/crowdsec-and-multiple-public-ips/2774)

<div class="topic-metadata">

**Author:** [@Sumi](https://discourse.crowdsec.net/u/Sumi)\
**Replies:** 0\
**Last updated:** [February 25, 2026, 10:39am UTC](https://discourse.crowdsec.net/t/crowdsec-and-multiple-public-ips/2774 "2026-02-25T10:39:54Z")

</div>

Hi everyone, I wanted to ask about something. I have an OPNsense firewall running, and Crowdsec is working well on it. I can see activity under Alerts and Decisions. However, I also have Postfix and RSPAMD running on …

---

## [Custom scenario labels (Behavior/MITRE/CVE) not appearing in CrowdSec Console](https://discourse.crowdsec.net/t/custom-scenario-labels-behavior-mitre-cve-not-appearing-in-crowdsec-console/2772)

<div class="topic-metadata">

**Author:** [@Lukes](https://discourse.crowdsec.net/u/Lukes)\
**Replies:** 1\
**Last updated:** [February 23, 2026, 11:12am UTC](https://discourse.crowdsec.net/t/custom-scenario-labels-behavior-mitre-cve-not-appearing-in-crowdsec-console/2772 "2026-02-23T11:12:24Z")

</div>

Hello, Is it possible to pass Behavior, MITRE technique, and CVE metrics to the CrowdSec Console for custom scenarios? For my custom scenarios, I have defined the following labels: labels: remediation: true classi…

---

## [All working but nftables empty](https://discourse.crowdsec.net/t/all-working-but-nftables-empty/2771)

<div class="topic-metadata">

**Author:** [@TomTom](https://discourse.crowdsec.net/u/TomTom)\
**Replies:** 0\
**Last updated:** [February 20, 2026, 1:33pm UTC](https://discourse.crowdsec.net/t/all-working-but-nftables-empty/2771 "2026-02-20T13:33:19Z")

</div>

Hi, I just encountered the following problem: I received tons of emails about bans, always from the same IP addresses. After researching the server, I found that everything was running fine, but the NF tables were empty…

---

## [Activation email](https://discourse.crowdsec.net/t/activation-email/2768)

<div class="topic-metadata">

**Author:** [@Lukes](https://discourse.crowdsec.net/u/Lukes)\
**Replies:** 0\
**Last updated:** [February 14, 2026, 2:12pm UTC](https://discourse.crowdsec.net/t/activation-email/2768 "2026-02-14T14:12:51Z")

</div>

For some reason, I did not receive the email during registration in the CrowdSec Console, and there is no resend button available. When I try to register again or reset the password, I get the error: “An account linked t…

---

## [CrowdSec custom parser not recognizing timestamp](https://discourse.crowdsec.net/t/crowdsec-custom-parser-not-recognizing-timestamp/2765)

<div class="topic-metadata">

**Author:** [@Lukes](https://discourse.crowdsec.net/u/Lukes)\
**Replies:** 0\
**Last updated:** [February 11, 2026, 12:29pm UTC](https://discourse.crowdsec.net/t/crowdsec-custom-parser-not-recognizing-timestamp/2765 "2026-02-11T12:29:55Z")

</div>

Hi all, I’m new to CrowdSec and I’m trying to create a custom parser for Stalwart logs. My logs look like this: 2026-02-11T08:16:01Z INFO Banned due to scan (security.scan-ban) listenerId = "smtp", localPort = 25, rem…

---

## [Need help. Is it a bug?](https://discourse.crowdsec.net/t/need-help-is-it-a-bug/2763)

<div class="topic-metadata">

**Author:** [@coloradobug](https://discourse.crowdsec.net/u/coloradobug)\
**Replies:** 0\
**Last updated:** [February 11, 2026, 8:34am UTC](https://discourse.crowdsec.net/t/need-help-is-it-a-bug/2763 "2026-02-11T08:34:15Z")

</div>

Good day. First of all, I apologize for the machine translation; English is not my native language. Recently, something strange has been happening with the program. Let me explain step by step. We have Crowdsec install…

[Next page](https://discourse.crowdsec.net/c/crowdsec/5.md?page=1)
