Can you use crowdsec on an IoT device?
Is it possible to lockout the user account(not just IP ban) after certain number of failed logins.

Depending on what services the IoT device uses, certainly. It is one of the intended uses.

Yes, while most people use crowdsec to ban ip addresses, a decisions can be of any kind and target any scope, as long as you have a bouncer to deal with it.

When you say “lockout the user account”, at which level are you referring to ? (ie. within an application ?)

User account used to login to web interface, telnet/ssh, etc,.

Is there a generic bouncer for Account lockout?