# Alerts and détection issue

**URL:** <https://discourse.crowdsec.net/t/alerts-and-detection-issue/471>\
**Category:** Uncategorized\
**Created:** [December 22, 2021, 7:35am UTC](https://discourse.crowdsec.net/t/alerts-and-detection-issue/471 "2021-12-22T07:35:10Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Petre](https://avatars.discourse-cdn.com/v4/letter/p/bc8723/32.png) [@Petre](https://discourse.crowdsec.net/u/Petre)\
**Post date:** [December 22, 2021, 7:35am UTC](https://discourse.crowdsec.net/t/alerts-and-detection-issue/471/1 "2021-12-22T07:35:10Z")

</div>

Hy everyone

I installed crowdsec in my ubuntu virtual machine with nginx and ssh .  
. In another private network i have a kali Linux and i made thé scan to crowdsec machine with nikto and hydra for ssh. I see all in my log auth.log for ssh and accès.log for nginx but the crowdsec do nothing.  
When i made cscli alerts list i see nothing.  
Question . Crowdsec détect and alert if the attaque comming from a private network?

Thanks

---

<div class="post-metadata">

**Author:** ![klausagnoletti](https://dub1.discourse-cdn.com/flex013/user_avatar/discourse.crowdsec.net/klausagnoletti/32/201_2.png) [@klausagnoletti](https://discourse.crowdsec.net/u/klausagnoletti)\
**Post date:** [December 22, 2021, 10:39am UTC](https://discourse.crowdsec.net/t/alerts-and-detection-issue/471/2 "2021-12-22T10:39:41Z")

</div>

Hey

Thanks for reaching out. Could you elaborate on what you have installed? Did you follow the install [instructions](https://doc.crowdsec.net/docs/getting_started/install_crowdsec)? And did you install both the CrowdSec agent and a bouncer? If so, which bouncer and did you verify that the bouncer is properly registered with the agent?

Thanks!

---

<div class="post-metadata">

**Author:** ![alteredCoder](https://dub1.discourse-cdn.com/flex013/user_avatar/discourse.crowdsec.net/alteredcoder/32/44_2.png) [@alteredCoder](https://discourse.crowdsec.net/u/alteredCoder)\
**Post date:** [December 22, 2021, 10:50am UTC](https://discourse.crowdsec.net/t/alerts-and-detection-issue/471/3 "2021-12-22T10:50:46Z")

</div>

Hello @Petre,

If you run `cscli parsers list` , does the parser `crowdsecurity/whitelists` is installed ?  
If yes, this parser whitelist private IP address. So for your tests, you might want to delete it by running `sudo cscli parsers remove crowdsecurity/whitelists` (and reload crowdsec).

---

<div class="post-metadata">

**Author:** ![Petre](https://avatars.discourse-cdn.com/v4/letter/p/bc8723/32.png) [@Petre](https://discourse.crowdsec.net/u/Petre)\
**Post date:** [December 22, 2021, 1:21pm UTC](https://discourse.crowdsec.net/t/alerts-and-detection-issue/471/4 "2021-12-22T13:21:31Z")

</div>

Hello everyone  
Firstly thanks for thé reply  
I made thé changé with thé parser whitelist and thé issue is solved.  
Thanks
