# Uncategorized

**URL:** https://discourse.crowdsec.net/c/uncategorized/1.md?page=1

[Latest](https://discourse.crowdsec.net/latest.md) · [Categories](https://discourse.crowdsec.net/categories.md)

**Page:** 2

---

## [Unblock IP from Firewall Bouncer](https://discourse.crowdsec.net/t/unblock-ip-from-firewall-bouncer/1039)

<div class="topic-metadata">

**Author:** [@sv3jw](https://discourse.crowdsec.net/u/sv3jw)\
**Replies:** 1\
**Last updated:** [November 22, 2022, 3:26pm UTC](https://discourse.crowdsec.net/t/unblock-ip-from-firewall-bouncer/1039 "2022-11-22T15:26:51Z")

</div>

I was testing a security check tool and scanned my own IP while still having my firewall bouncer on. My scan triggerd the bouncer and now my own IP is blocked. Is there a way to unblock my IP? Thanks in advance!

---

## [Crowdsec-firewall-bouncer in a container](https://discourse.crowdsec.net/t/crowdsec-firewall-bouncer-in-a-container/1730)

<div class="topic-metadata">

**Author:** [@stephdl](https://discourse.crowdsec.net/u/stephdl)\
**Replies:** 5\
**Last updated:** [May 9, 2025, 8:02pm UTC](https://discourse.crowdsec.net/t/crowdsec-firewall-bouncer-in-a-container/1730 "2025-05-09T20:02:00Z")

</div>

Hello Ready to get (in french) ‘une volée de bois vert’, but we are experimenting a way to use crowdsec-firewall-bouncer in a container. We used to install it on the host with deb or rpm but this time we tried to get …

---

## [Daily anacron Mails](https://discourse.crowdsec.net/t/daily-anacron-mails/2409)

<div class="topic-metadata">

**Author:** [@Benjamin](https://discourse.crowdsec.net/u/Benjamin)\
**Replies:** 2\
**Last updated:** [April 13, 2025, 6:07pm UTC](https://discourse.crowdsec.net/t/daily-anacron-mails/2409 "2025-04-13T18:07:21Z")

</div>

Hello i have been receiving this email every day for a few weeks. How can i turn it off ? /etc/cron.daily/crowdsec: Downloading /etc/crowdsec/hub/.index.json crowdsecurity/base-http-scenarios is outdated because of sc…

---

## [Documentation NPM + Crowdsec seems no longer to work](https://discourse.crowdsec.net/t/documentation-npm-crowdsec-seems-no-longer-to-work/2491)

<div class="topic-metadata">

**Author:** [@Legolas](https://discourse.crowdsec.net/u/Legolas)\
**Replies:** 0\
**Last updated:** [April 10, 2025, 6:27am UTC](https://discourse.crowdsec.net/t/documentation-npm-crowdsec-seems-no-longer-to-work/2491 "2025-04-10T06:27:36Z")

</div>

Hi, this Doc seems no longer working: Protect Your Websites with CrowdSec and Nginx Proxy Manager. If i try to replace the image with this: image: 'Lepresidente/nginxproxymanager:latest' i get this error: ✘ nginx\_pr…

---

## [Alerts and decicions show, but ip is not blocked](https://discourse.crowdsec.net/t/alerts-and-decicions-show-but-ip-is-not-blocked/2464)

<div class="topic-metadata">

**Author:** [@Joseppe](https://discourse.crowdsec.net/u/Joseppe)\
**Replies:** 12\
**Last updated:** [March 31, 2025, 7:54pm UTC](https://discourse.crowdsec.net/t/alerts-and-decicions-show-but-ip-is-not-blocked/2464 "2025-03-31T19:54:52Z")

</div>

I have a crowdsec container watching logs of a vaultwarden instance und on the docker host a bouncer wich as far as i can see seems i got to work fine (but i am not sure :slight\_smile: I see the alerts, i see decisions,…

---

## [Ban IP works only for the Hello World application](https://discourse.crowdsec.net/t/ban-ip-works-only-for-the-hello-world-application/2472)

<div class="topic-metadata">

**Author:** [@akshay\_14583](https://discourse.crowdsec.net/u/akshay_14583)\
**Replies:** 0\
**Last updated:** [March 30, 2025, 10:59am UTC](https://discourse.crowdsec.net/t/ban-ip-works-only-for-the-hello-world-application/2472 "2025-03-30T10:59:56Z")

</div>

Hi..I have deployed crowdsec on K8S ( removed whitelist + logs capture the private ip )and have installed the nginx-ingress bouncer..On the Hello World Application post rate-limit-exceeded the private ip is getting banne…

---

## [Ip ranges, cs-firewall-bouncer and nftables](https://discourse.crowdsec.net/t/ip-ranges-cs-firewall-bouncer-and-nftables/296)

<div class="topic-metadata">

**Author:** [@lleddewk](https://discourse.crowdsec.net/u/lleddewk)\
**Replies:** 5\
**Last updated:** [March 17, 2025, 3:09pm UTC](https://discourse.crowdsec.net/t/ip-ranges-cs-firewall-bouncer-and-nftables/296 "2025-03-17T15:09:47Z")

</div>

When using cs-firewall-bouncer with nftables, it does not appear to be possible to ban ranges of ip addresses. For example, after adding a range using sudo cscli decisions add --range 1.2.3.0/24, inspecting the content …

---

## [Custom pipline of parsers and profiles](https://discourse.crowdsec.net/t/custom-pipline-of-parsers-and-profiles/2433)

<div class="topic-metadata">

**Author:** [@Vindek](https://discourse.crowdsec.net/u/Vindek)\
**Replies:** 0\
**Last updated:** [March 14, 2025, 3:15am UTC](https://discourse.crowdsec.net/t/custom-pipline-of-parsers-and-profiles/2433 "2025-03-14T03:15:47Z")

</div>

Hello! I want to write my own parsers, scenarios and profiles and during their creation I want to observe how data in json format or in another form is sent between them so that I can write processing templates

---

## [Parser for 2 Log-Lines](https://discourse.crowdsec.net/t/parser-for-2-log-lines/2395)

<div class="topic-metadata">

**Author:** [@dedmaross](https://discourse.crowdsec.net/u/dedmaross)\
**Replies:** 5\
**Last updated:** [February 28, 2025, 12:14pm UTC](https://discourse.crowdsec.net/t/parser-for-2-log-lines/2395 "2025-02-28T12:14:53Z")

</div>

Hi, ive got a log which consist of several lines. i need to extract from 1 line the remote ip-adress and from other line the message text for bad login. I dont know how to combine the 2 lines for one event Could anybo…

---

## [Pattern for Radicale Log](https://discourse.crowdsec.net/t/pattern-for-radicale-log/2378)

<div class="topic-metadata">

**Author:** [@dedmaross](https://discourse.crowdsec.net/u/dedmaross)\
**Replies:** 2\
**Last updated:** [February 27, 2025, 6:07pm UTC](https://discourse.crowdsec.net/t/pattern-for-radicale-log/2378 "2025-02-27T18:07:43Z")

</div>

Hi, im trying to create bf detection for radicale caldav server. Im not getting the correct pattern for log, thinking the \<'\> ist the problem. Could anyone plz help for the correct pattern-line. This pattern doesnt wor…

---

## [Centralized management scenarios](https://discourse.crowdsec.net/t/centralized-management-scenarios/837)

<div class="topic-metadata">

**Author:** [@fayataf488](https://discourse.crowdsec.net/u/fayataf488)\
**Replies:** 4\
**Last updated:** [February 26, 2025, 9:20am UTC](https://discourse.crowdsec.net/t/centralized-management-scenarios/837 "2025-02-26T09:20:02Z")

</div>

How to centrally manage scenarios? Is it possible to roll scenarios through lapi somehow? Can’t you do this with crowdsec?

---

## [Dyndns whitelist](https://discourse.crowdsec.net/t/dyndns-whitelist/2382)

<div class="topic-metadata">

**Author:** [@ohv](https://discourse.crowdsec.net/u/ohv)\
**Replies:** 1\
**Last updated:** [February 24, 2025, 9:52am UTC](https://discourse.crowdsec.net/t/dyndns-whitelist/2382 "2025-02-24T09:52:30Z")

</div>

level=warning msg=“failed to run whitelist expr : cannot get Source from Alert (1:5)\\n | evt.Overflow.Alert.Source.IP in LookupHost("string-dc-njhgrpjwrm.dynamic-m.com")\\n | …^” id=little-meadow name=me/FQDN-whitlists st…

---

## [Discord notification like Telegram/gotify](https://discourse.crowdsec.net/t/discord-notification-like-telegram-gotify/2368)

<div class="topic-metadata">

**Author:** [@daschmidt](https://discourse.crowdsec.net/u/daschmidt)\
**Replies:** 0\
**Last updated:** [February 17, 2025, 9:29am UTC](https://discourse.crowdsec.net/t/discord-notification-like-telegram-gotify/2368 "2025-02-17T09:29:27Z")

</div>

Is it possible to get the same notificaition from the telegram docs? ▶ Summary I like it with the url for crowdsec cti and shodan. The discord notification work but I’m not able to format the text right.

---

## [Went to add crowdsec to exchange, do I need another](https://discourse.crowdsec.net/t/went-to-add-crowdsec-to-exchange-do-i-need-another/2362)

<div class="topic-metadata">

**Author:** [@ohv](https://discourse.crowdsec.net/u/ohv)\
**Replies:** 1\
**Last updated:** [February 16, 2025, 7:44pm UTC](https://discourse.crowdsec.net/t/went-to-add-crowdsec-to-exchange-do-i-need-another/2362 "2025-02-16T19:44:21Z")

</div>

No body reads this so why keep it up

---

## [Crowdsec ban 4h but firewall-bouncer for 5 minutes](https://discourse.crowdsec.net/t/crowdsec-ban-4h-but-firewall-bouncer-for-5-minutes/2364)

<div class="topic-metadata">

**Author:** [@pacs](https://discourse.crowdsec.net/u/pacs)\
**Replies:** 0\
**Last updated:** [February 16, 2025, 2:27pm UTC](https://discourse.crowdsec.net/t/crowdsec-ban-4h-but-firewall-bouncer-for-5-minutes/2364 "2025-02-16T14:27:27Z")

</div>

Hi, My setup consist on crowdsec docjker container and a firewall bouncer running s a service on host. I realize that crowdsec ban the IPs for 4h but in the ipset lists the duration is 5 minutes. Why ipset don’t appl…

---

## [IPset timeout value and profile ban time](https://discourse.crowdsec.net/t/ipset-timeout-value-and-profile-ban-time/1983)

<div class="topic-metadata">

**Author:** [@Kaspar](https://discourse.crowdsec.net/u/Kaspar)\
**Replies:** 3\
**Last updated:** [February 16, 2025, 2:22pm UTC](https://discourse.crowdsec.net/t/ipset-timeout-value-and-profile-ban-time/1983 "2025-02-16T14:22:54Z")

</div>

I am new to CrowSec and struggle to see the relation between the ban time defined in the profiles.yaml file (4 hours by default) and the timeout value used for IP’s in the ipset list. The timeout value on IP’s in the ip…

---

## [Captcha Decision for ASNs?](https://discourse.crowdsec.net/t/captcha-decision-for-asns/2356)

<div class="topic-metadata">

**Author:** [@sepplK](https://discourse.crowdsec.net/u/sepplK)\
**Replies:** 0\
**Last updated:** [February 14, 2025, 10:42pm UTC](https://discourse.crowdsec.net/t/captcha-decision-for-asns/2356 "2025-02-14T22:42:44Z")

</div>

Hi, is it possible to use captcha for ASN Numbers ? Thanks for help Sebastian

---

## [1.6.5 daily script](https://discourse.crowdsec.net/t/1-6-5-daily-script/2351)

<div class="topic-metadata">

**Author:** [@TryingHard](https://discourse.crowdsec.net/u/TryingHard)\
**Replies:** 2\
**Last updated:** [February 11, 2025, 8:46am UTC](https://discourse.crowdsec.net/t/1-6-5-daily-script/2351 "2025-02-11T08:46:59Z")

</div>

Hi, it appears that 1.6.5 on debian installed a new maintenance script. When there is nothing to do, this script’s output is: “Nothing to do, the hub index is up to date.” This leads to an e-mail every day telling me t…

---

## [OpenWRT and crowdesc-firewall-bouncer issue](https://discourse.crowdsec.net/t/openwrt-and-crowdesc-firewall-bouncer-issue/2346)

<div class="topic-metadata">

**Author:** [@updatelee](https://discourse.crowdsec.net/u/updatelee)\
**Replies:** 1\
**Last updated:** [February 7, 2025, 8:29pm UTC](https://discourse.crowdsec.net/t/openwrt-and-crowdesc-firewall-bouncer-issue/2346 "2025-02-07T20:29:42Z")

</div>

Problem: decisions arent being added time="2025-02-07T13:32:18Z" level=error msg="unable to commit add decisions failed to get current state: Receive: netlink receive: no such file or directory" crowdsec is being run o…

---

## [Crowdsec on pfsense 2.7.2 and outgoing SFTP](https://discourse.crowdsec.net/t/crowdsec-on-pfsense-2-7-2-and-outgoing-sftp/2338)

<div class="topic-metadata">

**Author:** [@Arti](https://discourse.crowdsec.net/u/Arti)\
**Replies:** 2\
**Last updated:** [February 5, 2025, 4:27pm UTC](https://discourse.crowdsec.net/t/crowdsec-on-pfsense-2-7-2-and-outgoing-sftp/2338 "2025-02-05T16:27:37Z")

</div>

Hi, I have installed the latest version of crowdsec on pfsense 2.7.2. First I clicked on “Apply to all interfaces”. But then outgoing SFTP via port 22 no longer works (if I deactivate the two crowdsec services, it wor…

---

## [Crowdsec in DMZ](https://discourse.crowdsec.net/t/crowdsec-in-dmz/2333)

<div class="topic-metadata">

**Author:** [@Twister844](https://discourse.crowdsec.net/u/Twister844)\
**Replies:** 0\
**Last updated:** [February 5, 2025, 7:54am UTC](https://discourse.crowdsec.net/t/crowdsec-in-dmz/2333 "2025-02-05T07:54:41Z")

</div>

Hello everyone, I discovered the crowdsec solution 3 months ago and would like to implement it on a machine at the hospital where I work. The context is as follows, we have a Windows with IIS in ARR mode for our Webmai…

---

## [Crowdsec NPM blocking is not working](https://discourse.crowdsec.net/t/crowdsec-npm-blocking-is-not-working/2269)

<div class="topic-metadata">

**Author:** [@upuldi](https://discourse.crowdsec.net/u/upuldi)\
**Replies:** 1\
**Last updated:** [February 3, 2025, 5:18am UTC](https://discourse.crowdsec.net/t/crowdsec-npm-blocking-is-not-working/2269 "2025-02-03T05:18:00Z")

</div>

I’ve set up CrowdSec with my Nginx Proxy Manager using Docker. Below is my configuration: nginx: image: lepresidente/nginx-proxy-manager:latest container\_name: nginx environment: - PUID=$PUID - PGID=$PG…

---

## [The Crowdsec service does not start when I use my mullvad VPN. ](https://discourse.crowdsec.net/t/the-crowdsec-service-does-not-start-when-i-use-my-mullvad-vpn/2328)

<div class="topic-metadata">

**Author:** [@fever7-beep](https://discourse.crowdsec.net/u/fever7-beep)\
**Replies:** 0\
**Last updated:** [February 1, 2025, 6:20pm UTC](https://discourse.crowdsec.net/t/the-crowdsec-service-does-not-start-when-i-use-my-mullvad-vpn/2328 "2025-02-01T18:20:18Z")

</div>

Hello everyone, I’m running Windows 11. The Crowdsec service does not start when I use my mullvad VPN. Which file to put in split tunneling so that the service starts automatically. Thanks in advance!

---

## [Api server init - unable to run local API authenticate watcher](https://discourse.crowdsec.net/t/api-server-init-unable-to-run-local-api-authenticate-watcher/2306)

<div class="topic-metadata">

**Author:** [@ianpmurphy](https://discourse.crowdsec.net/u/ianpmurphy)\
**Replies:** 2\
**Last updated:** [January 24, 2025, 11:29am UTC](https://discourse.crowdsec.net/t/api-server-init-unable-to-run-local-api-authenticate-watcher/2306 "2025-01-24T11:29:31Z")

</div>

Hi, I have crowdsec set up with HAProxy and it was been working for some time. I’ve just noticed that it is no longer working and this may be due to my having updated everything on my server (ubuntu). the error I get in…

---

## [How to confirm decisions have been taken](https://discourse.crowdsec.net/t/how-to-confirm-decisions-have-been-taken/2260)

<div class="topic-metadata">

**Author:** [@krautsec](https://discourse.crowdsec.net/u/krautsec)\
**Replies:** 7\
**Last updated:** [January 16, 2025, 12:12pm UTC](https://discourse.crowdsec.net/t/how-to-confirm-decisions-have-been-taken/2260 "2025-01-16T12:12:57Z")

</div>

Hi all, This is confusing. Could anyone explain please what\`s going on? On the engine dashboard on crowdsec.net I see a few alerts each with a label ‘1 decision’. See example: However, when navigating to ‘decisions…

---

## [Secure Nginx Proxy Manager Docker Instance with Crowdsec?](https://discourse.crowdsec.net/t/secure-nginx-proxy-manager-docker-instance-with-crowdsec/2125)

<div class="topic-metadata">

**Author:** [@dfgsdgsdgsd](https://discourse.crowdsec.net/u/dfgsdgsdgsd)\
**Replies:** 10\
**Last updated:** [January 6, 2025, 8:57pm UTC](https://discourse.crowdsec.net/t/secure-nginx-proxy-manager-docker-instance-with-crowdsec/2125 "2025-01-06T20:57:17Z")

</div>

Hi, is it possible to secure a docker instance of Nginx Proxy Manager with Crowdsec (native insalled on this Ubunut 24.0.4 VPS Server)? Im using this image for the NPM: jc21/nginx-proxy-manager:latest I learned that c…

---

## [Why does CrowdSec in Traefik return a 403 Forbidden error when using a MySQL database?](https://discourse.crowdsec.net/t/why-does-crowdsec-in-traefik-return-a-403-forbidden-error-when-using-a-mysql-database/2246)

<div class="topic-metadata">

**Author:** [@afrzlfa](https://discourse.crowdsec.net/u/afrzlfa)\
**Replies:** 2\
**Last updated:** [January 6, 2025, 11:52am UTC](https://discourse.crowdsec.net/t/why-does-crowdsec-in-traefik-return-a-403-forbidden-error-when-using-a-mysql-database/2246 "2025-01-06T11:52:24Z")

</div>

When using SQLite, everything works fine with no issues. However, when I switch to MySQL, I get a 403 Forbidden error. Here are the logs I’m getting: Crowdsec Log Traefik Log Note: The 403 Forbidden error does…

---

## [E-mail notifications: Include matching log line? Filter?](https://discourse.crowdsec.net/t/e-mail-notifications-include-matching-log-line-filter/2234)

<div class="topic-metadata">

**Author:** [@TryingHard](https://discourse.crowdsec.net/u/TryingHard)\
**Replies:** 3\
**Last updated:** [January 3, 2025, 4:21pm UTC](https://discourse.crowdsec.net/t/e-mail-notifications-include-matching-log-line-filter/2234 "2025-01-03T16:21:56Z")

</div>

Hi, is there a way to add a filter on which decisions lead to an e-mail notification? Ideally, I would only like to get a notification if an IP from a specific range is blocked. And is there a way to include the log li…

---

## [Error message from crowdsec](https://discourse.crowdsec.net/t/error-message-from-crowdsec/2216)

<div class="topic-metadata">

**Author:** [@FreddieOne](https://discourse.crowdsec.net/u/FreddieOne)\
**Replies:** 2\
**Last updated:** [December 27, 2024, 2:12pm UTC](https://discourse.crowdsec.net/t/error-message-from-crowdsec/2216 "2024-12-27T14:12:41Z")

</div>

Dear Community, I am new and I am self-taught. Thank you for this opportunity to ask my questions! I am running a synology nas 1821+, Container manager (docker), the following container: ddns-cloudflare-dns, Traefik 3.…

---

## [OpenWRT + SWAG + CrowdSec](https://discourse.crowdsec.net/t/openwrt-swag-crowdsec/2201)

<div class="topic-metadata">

**Author:** [@35ati](https://discourse.crowdsec.net/u/35ati)\
**Replies:** 2\
**Last updated:** [December 20, 2024, 12:53pm UTC](https://discourse.crowdsec.net/t/openwrt-swag-crowdsec/2201 "2024-12-20T12:53:05Z")

</div>

Hello, I want to introduce CrowdSec to my homelab and I would like some help please. My edge router/firewall if OpenWRT and I installed firewqll-bouncer on it. After that I have a host that runs a linuxserver.io swag …

[Previous page](https://discourse.crowdsec.net/c/uncategorized/1.md)

[Next page](https://discourse.crowdsec.net/c/uncategorized/1.md?page=2)
