Alerted IPs absent in iptables

Hi!
I installed CrowdSec on my Debian 12 and got 18 alerts last night. But none of the 18 IPs wasn’t blocked by iptables.
ipset does not have alerted IPs. Why? See pic attached.

grep with listed IP

So by default we impose a 4hr ban on the IP address, so it depends on when you check the ipset so if you run cscli alerts list and if they occur more than 4hr ago it safe to presume that the ban did happen and was in iptables but it simply expired.

You can find in the post installation guide how to alter your profiles if you want longer duration: