# Latest

**URL:** https://discourse.crowdsec.net/latest.md

[Latest](https://discourse.crowdsec.net/latest.md) · [Categories](https://discourse.crowdsec.net/categories.md)

---

## [Welcome to CrowdSecurity discourse!](https://discourse.crowdsec.net/t/welcome-to-crowdsecurity-discourse/7)

<div class="topic-metadata">

**Author:** [@system](https://discourse.crowdsec.net/u/system)\
**Replies:** 6\
**Last updated:** [August 4, 2020, 9:09am UTC](https://discourse.crowdsec.net/t/welcome-to-crowdsecurity-discourse/7 "2020-08-04T09:09:13Z")

</div>

This is a place to discuss the open-source software published by crowdsecurity. Here is a good place to exchange and learn about your experiences. Having trouble installing or configuring software components ? Having tr…

---

## [IPs fllagged as malicious in crowdsec still hitting my VPS. What can be the issue?](https://discourse.crowdsec.net/t/ips-fllagged-as-malicious-in-crowdsec-still-hitting-my-vps-what-can-be-the-issue/2930)

<div class="topic-metadata">

**Author:** [@bosunjohnson](https://discourse.crowdsec.net/u/bosunjohnson)\
**Replies:** 0\
**Last updated:** [September 21, 2026, 12:11pm UTC](https://discourse.crowdsec.net/t/ips-fllagged-as-malicious-in-crowdsec-still-hitting-my-vps-what-can-be-the-issue/2930 "2026-09-21T12:11:10Z")

</div>

I am sharing this as an example. I am still struggling to know how crowdsec works. I have some VPS with fail2ban but I just decided to include crowdsec a few days ago. I see IPs like this trying to brute force and acces…

---

## [Crowdsec decision expiration](https://discourse.crowdsec.net/t/crowdsec-decision-expiration/2920)

<div class="topic-metadata">

**Author:** [@Emmanuel](https://discourse.crowdsec.net/u/Emmanuel)\
**Replies:** 0\
**Last updated:** [August 26, 2026, 1:04pm UTC](https://discourse.crowdsec.net/t/crowdsec-decision-expiration/2920 "2026-08-26T13:04:22Z")

</div>

I have a crowdsec setup with a central server: Log Centralization | CrowdSec (a similar setup to this) The central server receives those logs and writes them into files. The Security Engine then analyzes those logs on…

---

## [Feature request - High Availability Support](https://discourse.crowdsec.net/t/feature-request-high-availability-support/2919)

<div class="topic-metadata">

**Author:** [@j0nny55555](https://discourse.crowdsec.net/u/j0nny55555)\
**Replies:** 0\
**Last updated:** [August 6, 2026, 6:13pm UTC](https://discourse.crowdsec.net/t/feature-request-high-availability-support/2919 "2026-08-06T18:13:31Z")

</div>

While the free option with one Engine is great, it would be amazing if we could use that (free one Engine) in an HA format. In this we would still be sending the same amount/group of parser/blocker/appsec agent data, bu…

---

## [AppSec (WAF) Feedback (Poll)](https://discourse.crowdsec.net/t/appsec-waf-feedback-poll/2264)

<div class="topic-metadata">

**Author:** [@iiAmLoz](https://discourse.crowdsec.net/u/iiAmLoz)\
**Replies:** 4\
**Last updated:** [August 1, 2026, 12:56pm UTC](https://discourse.crowdsec.net/t/appsec-waf-feedback-poll/2264 "2026-08-01T12:56:03Z")

</div>

Hey :wave: We appreciate your feedback on the current status of AppSec Component (WAF) and we currently see a lot of users not using this functionality compared to normal use of CrowdSec. Let us know the reason if you …

---

## [Question about Postoverflow rules](https://discourse.crowdsec.net/t/question-about-postoverflow-rules/2918)

<div class="topic-metadata">

**Author:** [@rbaino](https://discourse.crowdsec.net/u/rbaino)\
**Replies:** 0\
**Last updated:** [July 9, 2026, 6:03am UTC](https://discourse.crowdsec.net/t/question-about-postoverflow-rules/2918 "2026-07-09T06:03:49Z")

</div>

Hi everyone, I struggle a bit with using Postoverflow rules. For a Nextcloud instance I am testing CrowdSec + AppSec with, although having the Nextcloud Whitelist ruleset installed, I still need to whiteliste a few thin…

---

## [No se define API Key al momento de instalar bouncer nftables](https://discourse.crowdsec.net/t/no-se-define-api-key-al-momento-de-instalar-bouncer-nftables/2917)

<div class="topic-metadata">

**Author:** [@jteran](https://discourse.crowdsec.net/u/jteran)\
**Replies:** 0\
**Last updated:** [July 7, 2026, 1:07am UTC](https://discourse.crowdsec.net/t/no-se-define-api-key-al-momento-de-instalar-bouncer-nftables/2917 "2026-07-07T01:07:26Z")

</div>

Hola muchachos como va? Aqui les dejo una issue en la instalacion del paquete crowdsec-firewall-bouncer-nftables 0.0.34; Les dejo la secuencia de comandos que se usaron para resolverlo: dpkg -l | grep crowdsec apt-cac…

---

## [Line 0/1 is missing evt.StrTime](https://discourse.crowdsec.net/t/line-0-1-is-missing-evt-strtime/2916)

<div class="topic-metadata">

**Author:** [@Thomas](https://discourse.crowdsec.net/u/Thomas)\
**Replies:** 0\
**Last updated:** [July 5, 2026, 3:17pm UTC](https://discourse.crowdsec.net/t/line-0-1-is-missing-evt-strtime/2916 "2026-07-05T15:17:03Z")

</div>

how to get ride of this line ? I’m on a debian 12 with CrowdSec version: v1.7.8-debian-pragmatic-amd64-63227459 Codename: alphaga BuildDate: 2026-05-11\_12:32:51 GoVersion: 1.26.2 Platform: linux libre2: C++ I spend…

---

## [CrowdSec Parser for Stalwart Logs](https://discourse.crowdsec.net/t/crowdsec-parser-for-stalwart-logs/2800)

<div class="topic-metadata">

**Author:** [@Mic2026](https://discourse.crowdsec.net/u/Mic2026)\
**Replies:** 19\
**Last updated:** [July 3, 2026, 6:12am UTC](https://discourse.crowdsec.net/t/crowdsec-parser-for-stalwart-logs/2800 "2026-07-03T06:12:23Z")

</div>

2.687 Hello CrowdSec Community, I’ve been using CrowdSec as an extension in the reverse proxy Caddy for quite some time, but I’m new to the community. Everything is running in a Docker Compose instance with its own …

---

## [Using Wordfence IP blockings (Wordpress WAF) for Crowdsec decisions](https://discourse.crowdsec.net/t/using-wordfence-ip-blockings-wordpress-waf-for-crowdsec-decisions/1921)

<div class="topic-metadata">

**Author:** [@Cyrille37](https://discourse.crowdsec.net/u/Cyrille37)\
**Replies:** 2\
**Last updated:** [June 17, 2026, 5:38am UTC](https://discourse.crowdsec.net/t/using-wordfence-ip-blockings-wordpress-waf-for-crowdsec-decisions/1921 "2026-06-17T05:38:37Z")

</div>

Hi, Wordfence is a great Wordpress WAF with many options for blocking IP on some unwanted behaviors. I did not find any thing on Internet about Crowdsec scenario using Wordfence blockings to take decision. I would like…

---

## [Decision not listed](https://discourse.crowdsec.net/t/decision-not-listed/1943)

<div class="topic-metadata">

**Author:** [@Tammes](https://discourse.crowdsec.net/u/Tammes)\
**Replies:** 12\
**Last updated:** [June 5, 2026, 12:42pm UTC](https://discourse.crowdsec.net/t/decision-not-listed/1943 "2026-06-05T12:42:14Z")

</div>

Hello, I have set up crowdsec 1.6.2 as multiserver setup on debian servers and installed the crowdsecurity/linux collection (which includes sshd) and the iptables firewall bouncer. When I try to ssh into a non existent …

---

## [Appsec triggers alerts, but no decisions](https://discourse.crowdsec.net/t/appsec-triggers-alerts-but-no-decisions/2872)

<div class="topic-metadata">

**Author:** [@dani](https://discourse.crowdsec.net/u/dani)\
**Replies:** 2\
**Last updated:** [June 1, 2026, 9:53am UTC](https://discourse.crowdsec.net/t/appsec-triggers-alerts-but-no-decisions/2872 "2026-06-01T09:53:02Z")

</div>

Hi. I’m just prototyping Crowdsec, inluding appsec. I have a multi node setups Some (1 for now) dedicated log-processors, which receive logs from an HTTP datasource Some (1 for now) local-api The logs part is working …

---

## [TLS handshake timeout to https://api.crowdsec.net/](https://discourse.crowdsec.net/t/tls-handshake-timeout-to-https-api-crowdsec-net/2874)

<div class="topic-metadata">

**Author:** [@pedrobuffon](https://discourse.crowdsec.net/u/pedrobuffon)\
**Replies:** 1\
**Last updated:** [May 29, 2026, 4:37pm UTC](https://discourse.crowdsec.net/t/tls-handshake-timeout-to-https-api-crowdsec-net/2874 "2026-05-29T16:37:07Z")

</div>

i had to recreate my docker volumes, when crowdsec docker was creating the files i notice some weird behavior when it came to connecting to the https://api.crowdsec.net/, online\_api\_credentials.yaml was not being auto fi…

---

## [Best way to disable crowdsec for specific domain?](https://discourse.crowdsec.net/t/best-way-to-disable-crowdsec-for-specific-domain/2817)

<div class="topic-metadata">

**Author:** [@lexuzieel](https://discourse.crowdsec.net/u/lexuzieel)\
**Replies:** 0\
**Last updated:** [May 26, 2026, 1:59am UTC](https://discourse.crowdsec.net/t/best-way-to-disable-crowdsec-for-specific-domain/2817 "2026-05-26T01:59:02Z")

</div>

I have Crowdsec setup with Caddy and I am considering being able to enable/disable it for particular hosts (similar to how you can disable WAF in Cloudflare). I have stumbled upon this: Allowlisting and Rule Overrides | …

---

## [Unable to login with Google](https://discourse.crowdsec.net/t/unable-to-login-with-google/2815)

<div class="topic-metadata">

**Author:** [@matthys70](https://discourse.crowdsec.net/u/matthys70)\
**Replies:** 0\
**Last updated:** [May 16, 2026, 1:08pm UTC](https://discourse.crowdsec.net/t/unable-to-login-with-google/2815 "2026-05-16T13:08:16Z")

</div>

Anyone else with the same issue? If I try to get to my dashboard and login with Google I get: Oops… an error occurred while fetching the user data. Try to go back or reload this page, if the problem persists, please c…

---

## [Still no package for fedora newer than 39?](https://discourse.crowdsec.net/t/still-no-package-for-fedora-newer-than-39/2811)

<div class="topic-metadata">

**Author:** [@Thenesis](https://discourse.crowdsec.net/u/Thenesis)\
**Replies:** 0\
**Last updated:** [May 12, 2026, 8:29am UTC](https://discourse.crowdsec.net/t/still-no-package-for-fedora-newer-than-39/2811 "2026-05-12T08:29:51Z")

</div>

Is there a reason why crowdsec did stop the development of crowdsec for fedora? We are at fedora 44 atm and nothing.

---

## [Improved exim parser](https://discourse.crowdsec.net/t/improved-exim-parser/2807)

<div class="topic-metadata">

**Author:** [@matthys70](https://discourse.crowdsec.net/u/matthys70)\
**Replies:** 0\
**Last updated:** [May 10, 2026, 12:43pm UTC](https://discourse.crowdsec.net/t/improved-exim-parser/2807 "2026-05-10T12:43:13Z")

</div>

I just noticed my exim parser at /etc/crowdsec/parsers/s01-parse/exim-logs.yaml was not working well. Even if it was parsing a very default exim4 mainlog file. I just want to share my current modified one (exim-logs.yam…

---

## [Running crowdsec as non-root user in Docker?](https://discourse.crowdsec.net/t/running-crowdsec-as-non-root-user-in-docker/2021)

<div class="topic-metadata">

**Author:** [@verybadsoldier](https://discourse.crowdsec.net/u/verybadsoldier)\
**Replies:** 5\
**Last updated:** [April 30, 2026, 10:05pm UTC](https://discourse.crowdsec.net/t/running-crowdsec-as-non-root-user-in-docker/2021 "2026-04-30T22:05:53Z")

</div>

Hi everyone, I am new to crowdsec and I have set up crowdsec using the Docker container from here in my home lab: https://hub.docker.com/r/crowdsecurity/crowdsec The container seems to running as root by default. Is i…

---

## [CrowdSec Appsec doesn't process JSON/XML](https://discourse.crowdsec.net/t/crowdsec-appsec-doesnt-process-json-xml/2787)

<div class="topic-metadata">

**Author:** [@oleksandr.yashchenko](https://discourse.crowdsec.net/u/oleksandr.yashchenko)\
**Replies:** 3\
**Last updated:** [April 22, 2026, 4:28pm UTC](https://discourse.crowdsec.net/t/crowdsec-appsec-doesnt-process-json-xml/2787 "2026-04-22T16:28:53Z")

</div>

Dear Community, During the migration to Crowdsec AppSec engine, we’ve noticed that JSON/XML request body headers aren’t processed automatically. It used to work for NGINX + ModSec + CRS stack. Environment: CrowdSec …

---

## [Haproxy spoa bouncer latency](https://discourse.crowdsec.net/t/haproxy-spoa-bouncer-latency/2799)

<div class="topic-metadata">

**Author:** [@jschaeff](https://discourse.crowdsec.net/u/jschaeff)\
**Replies:** 2\
**Last updated:** [April 16, 2026, 10:44am UTC](https://discourse.crowdsec.net/t/haproxy-spoa-bouncer-latency/2799 "2026-04-16T10:44:05Z")

</div>

Hello, I’m setting up the haproxy bouncer and it works great. We noticed that it adds a 500ms latency for all requests, and I could not find how to minimize it. First question : is such a latency expected ? If not wha…

---

## [IP Public was blacklisted](https://discourse.crowdsec.net/t/ip-public-was-blacklisted/2798)

<div class="topic-metadata">

**Author:** [@abrenon](https://discourse.crowdsec.net/u/abrenon)\
**Replies:** 1\
**Last updated:** [April 13, 2026, 11:18am UTC](https://discourse.crowdsec.net/t/ip-public-was-blacklisted/2798 "2026-04-13T11:18:40Z")

</div>

Hi, My IP Public is blacklisted by crowdsec but i’m not administrator pf crowdsec. I was blacklisted for access to a partner platform … The problem was multiple query with a bad parameter, so i just change parameter so…

---

## [Home assistant logs not parsed](https://discourse.crowdsec.net/t/home-assistant-logs-not-parsed/948)

<div class="topic-metadata">

**Author:** [@krisbogaerts](https://discourse.crowdsec.net/u/krisbogaerts)\
**Replies:** 5\
**Last updated:** [March 30, 2026, 4:28pm UTC](https://discourse.crowdsec.net/t/home-assistant-logs-not-parsed/948 "2026-03-30T16:28:29Z")

</div>

Hi, I installed the home assistant add-on, but the logs are not parsed, and it ignores failed logins or banned IP’s Also tried to cscli explain the logs directly but this does not seem to parse Configuration is …

---

## [Blocklist Integration with Check Point Firewall](https://discourse.crowdsec.net/t/blocklist-integration-with-check-point-firewall/2723)

<div class="topic-metadata">

**Author:** [@boombies](https://discourse.crowdsec.net/u/boombies)\
**Replies:** 9\
**Last updated:** [March 26, 2026, 7:07pm UTC](https://discourse.crowdsec.net/t/blocklist-integration-with-check-point-firewall/2723 "2026-03-26T19:07:20Z")

</div>

Has anyone successfully used the CrowdSec blocklist integration with a Check Point firewall IOC feed? Checkpoint | CrowdSec The documentation is pretty straight forward but it fails to pull the IOC feed. When putting th…

---

## [CrowdSec Appsec produces plenty of errors in OpenResty logs under high traffic](https://discourse.crowdsec.net/t/crowdsec-appsec-produces-plenty-of-errors-in-openresty-logs-under-high-traffic/2790)

<div class="topic-metadata">

**Author:** [@oleksandr.yashchenko](https://discourse.crowdsec.net/u/oleksandr.yashchenko)\
**Replies:** 1\
**Last updated:** [March 20, 2026, 4:46pm UTC](https://discourse.crowdsec.net/t/crowdsec-appsec-produces-plenty-of-errors-in-openresty-logs-under-high-traffic/2790 "2026-03-20T16:46:39Z")

</div>

Dear Community, Environment OS: Oracle Linux 9 OpenResty: v1.29.2.1 (ngx\_lua-0.10.29R2, lua-resty-http v0.12) CrowdSec: v1.7.6-rpm-pragmatic-amd64-eacc8192 CrowdSec OpenResty Bouncer: v1.1.1 AppSec: enabled, crowdsecu…

---

## [PostOverflow whitelists ONLY for specific scenarios](https://discourse.crowdsec.net/t/postoverflow-whitelists-only-for-specific-scenarios/2517)

<div class="topic-metadata">

**Author:** [@DuvelCorp](https://discourse.crowdsec.net/u/DuvelCorp)\
**Replies:** 2\
**Last updated:** [March 17, 2026, 8:34pm UTC](https://discourse.crowdsec.net/t/postoverflow-whitelists-only-for-specific-scenarios/2517 "2026-03-17T20:34:52Z")

</div>

Hi Basically I have this to whitelist some ASN of my country name: xxx/ASN-whitelist description: "Whitelist Trusted Belgian ASNs" #debug: true whitelist: reason: "xxx Whitelisted Belgian ASN" expression: - evt…

---

## [Can't start crowdsec in rootless podman](https://discourse.crowdsec.net/t/cant-start-crowdsec-in-rootless-podman/2788)

<div class="topic-metadata">

**Author:** [@Damncold](https://discourse.crowdsec.net/u/Damncold)\
**Replies:** 2\
**Last updated:** [March 15, 2026, 8:53pm UTC](https://discourse.crowdsec.net/t/cant-start-crowdsec-in-rootless-podman/2788 "2026-03-15T20:53:03Z")

</div>

Hi, im trying to get crowdsec running in rootless podman. But i get the following error: crowdsec-pangolin\[243452\]: ln: /var/lib/crowdsec/data/GeoLite2-ASN.mmdb: Permission denied I think the permissions are correct…

---

## [Frequent IP Bans by CrowdSec Due to Synapse Matrix Requests: Seeking Help and Solutions](https://discourse.crowdsec.net/t/frequent-ip-bans-by-crowdsec-due-to-synapse-matrix-requests-seeking-help-and-solutions/1472)

<div class="topic-metadata">

**Author:** [@alpha-ars](https://discourse.crowdsec.net/u/alpha-ars)\
**Replies:** 10\
**Last updated:** [March 13, 2026, 6:44pm UTC](https://discourse.crowdsec.net/t/frequent-ip-bans-by-crowdsec-due-to-synapse-matrix-requests-seeking-help-and-solutions/1472 "2026-03-13T18:44:12Z")

</div>

I’ve been facing a recurring issue with CrowdSec and wanted to share my experience and seek advice. My IP address has been getting banned quite often, and I suspect that it’s related to the requests made to my Synapse ma…

---

## [Whitelist ban by appsec](https://discourse.crowdsec.net/t/whitelist-ban-by-appsec/2785)

<div class="topic-metadata">

**Author:** [@soif-deconnaissance](https://discourse.crowdsec.net/u/soif-deconnaissance)\
**Replies:** 2\
**Last updated:** [March 13, 2026, 11:20am UTC](https://discourse.crowdsec.net/t/whitelist-ban-by-appsec/2785 "2026-03-13T11:20:43Z")

</div>

Hello everyone, I am encountering the following error with my GitLab server, which is behind NPMplus by Zoey2936 : 2026/03/10 15:12:09 \[alert\] 623#623: \*3881 \[lua\] crowdsec.lua:783: Allow(): \[Crowdsec\] denied '192.168.…

---

## [AppSec on VPS which do TLS passthrough to local machine behind CGNAT](https://discourse.crowdsec.net/t/appsec-on-vps-which-do-tls-passthrough-to-local-machine-behind-cgnat/2779)

<div class="topic-metadata">

**Author:** [@thingandstuff889](https://discourse.crowdsec.net/u/thingandstuff889)\
**Replies:** 4\
**Last updated:** [March 5, 2026, 10:20am UTC](https://discourse.crowdsec.net/t/appsec-on-vps-which-do-tls-passthrough-to-local-machine-behind-cgnat/2779 "2026-03-05T10:20:08Z")

</div>

Hi, First off thanks for making this wonderful piece of software. I have a specific setup like this: Client ⇒ VPS (Caddy L4 TLS passthrough) ⇒ (Wireguard) ⇒ Local machine (another Caddy do TLS termination) Currently I…

---

## [Appsec not working?](https://discourse.crowdsec.net/t/appsec-not-working/2778)

<div class="topic-metadata">

**Author:** [@urbaman](https://discourse.crowdsec.net/u/urbaman)\
**Replies:** 2\
**Last updated:** [March 3, 2026, 11:46am UTC](https://discourse.crowdsec.net/t/appsec-not-working/2778 "2026-03-03T11:46:00Z")

</div>

Hi, I’m trying to see if Appsec is working or not (cannot see any alerts triggered by appsec). sudo cscli appsec-configs list ────────────────────────────────────────────────────────────────────────────────────────────…

[Next page](https://discourse.crowdsec.net/latest.md?page=1)
