CrownSec Just not log my failed attemps

I have fix SQLITE WARNINGS. in this post

But i still not have any fail logs in /var/log/crowdsec.log

time=“09-12-2022 20:48:24” level=info msg=“Adding trigger bucket” cfg=frosty-snowflake file=/etc/crowdsec/scenarios/http-cve-2021-42013.yaml name=crowdsecurity/http-cve-2021-42013
time=“09-12-2022 20:48:24” level=info msg=“Adding leaky bucket” cfg=wispy-night file=/etc/crowdsec/scenarios/http-generic-bf.yaml name=crowdsecurity/http-generic-bf
time=“09-12-2022 20:48:24” level=info msg=“Adding leaky bucket” cfg=black-firefly file=/etc/crowdsec/scenarios/http-generic-bf.yaml name=LePresidente/http-generic-401-bf
time=“09-12-2022 20:48:24” level=info msg=“Adding trigger bucket” cfg=lingering-smoke file=/etc/crowdsec/scenarios/CVE-2022-42889.yaml name=crowdsecurity/CVE-2022-42889
time=“09-12-2022 20:48:24” level=info msg=“Adding trigger bucket” cfg=dry-water file=/etc/crowdsec/scenarios/CVE-2022-26134.yaml name=crowdsecurity/CVE-2022-26134
time=“09-12-2022 20:48:24” level=info msg=“Adding trigger bucket” cfg=small-brook file=/etc/crowdsec/scenarios/http-w00tw00t.yaml name=ltsich/http-w00tw00t
time=“09-12-2022 20:48:24” level=info msg=“Adding trigger bucket” cfg=nameless-water file=/etc/crowdsec/scenarios/CVE-2022-40684.yaml name=crowdsecurity/fortinet-cve-2022-40684
time=“09-12-2022 20:48:24” level=info msg=“Adding leaky bucket” cfg=lively-frog file=/etc/crowdsec/scenarios/http-crawl-non_statics.yaml name=crowdsecurity/http-crawl-non_statics
time=“09-12-2022 20:48:24” level=info msg=“Adding trigger bucket” cfg=snowy-pond file=/etc/crowdsec/scenarios/http-open-proxy.yaml name=crowdsecurity/http-open-proxy
time=“09-12-2022 20:48:24” level=warning msg=“Loaded 35 scenarios”
time=“09-12-2022 20:48:24” level=info msg=“loading acquisition file : /etc/crowdsec/acquis.yaml”
time=“09-12-2022 20:48:24” level=info msg=“Adding file /var/log/auth.log to datasources” type=file
time=“09-12-2022 20:48:24” level=info msg=“Adding file /var/log/mysql/error.log to datasources” type=file
time=“09-12-2022 20:48:24” level=info msg=“Adding file /var/log/syslog to datasources” type=file
time=“09-12-2022 20:48:24” level=info msg=“Adding file /var/log/kern.log to datasources” type=file
time=“09-12-2022 20:48:24” level=info msg=“Starting processing data”
time=“09-12-2022 20:48:24” level=info msg=“Running journalctl command: /usr/bin/journalctl [journalctl --follow -n 0 _SYSTEMD_UNIT=apache2.service]” src=“journalctl-_SYSTEMD_UNIT=apache2.service” type=journalctl

here is /var/log/auth.log

Connection closed by authenticating user test 10.0.5.30 port 61027 [preauth]
Dec 9 20:50:08 localhost sshd[60108]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=10.0.5.30 user=test
Dec 9 20:50:10 localhost sshd[60108]: Failed password for test from 10.0.5.30 port 61028 ssh2
Dec 9 20:50:19 localhost sshd[60108]: message repeated 2 times: [ Failed password for test from 10.0.5.30 port 61028 ssh2]
Dec 9 20:50:20 localhost sshd[60108]: Connection closed by authenticating user test 10.0.5.30 port 61028 [preauth]
Dec 9 20:50:20 localhost sshd[60108]: PAM 2 more authentication failures; logname= uid=0 euid=0 tty=ssh ruser= rhost=10.0.5.30 user=test