# CrownSec Just not log my failed attemps

**URL:** <https://discourse.crowdsec.net/t/crownsec-just-not-log-my-failed-attemps/1067>\
**Category:** Uncategorized\
**Created:** [December 9, 2022, 8:36pm UTC](https://discourse.crowdsec.net/t/crownsec-just-not-log-my-failed-attemps/1067 "2022-12-09T20:36:03Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![Rhandyx](https://dub1.discourse-cdn.com/flex013/user_avatar/discourse.crowdsec.net/rhandyx/32/493_2.png) [@Rhandyx](https://discourse.crowdsec.net/u/Rhandyx)\
**Post date:** [December 9, 2022, 8:58pm UTC](https://discourse.crowdsec.net/t/crownsec-just-not-log-my-failed-attemps/1067/2 "2022-12-09T20:58:43Z")

</div>

I have fix SQLITE WARNINGS. in this [post](https://discourse.crowdsec.net/t/warning-sqlite-without-wal-and-cannot-update-community-blocklist/1042/4)

But i still not have any fail logs in /var/log/crowdsec.log

> time=“09-12-2022 20:48:24” level=info msg=“Adding trigger bucket” cfg=frosty-snowflake file=/etc/crowdsec/scenarios/http-cve-2021-42013.yaml name=crowdsecurity/http-cve-2021-42013  
> time=“09-12-2022 20:48:24” level=info msg=“Adding leaky bucket” cfg=wispy-night file=/etc/crowdsec/scenarios/http-generic-bf.yaml name=crowdsecurity/http-generic-bf  
> time=“09-12-2022 20:48:24” level=info msg=“Adding leaky bucket” cfg=black-firefly file=/etc/crowdsec/scenarios/http-generic-bf.yaml name=LePresidente/http-generic-401-bf  
> time=“09-12-2022 20:48:24” level=info msg=“Adding trigger bucket” cfg=lingering-smoke file=/etc/crowdsec/scenarios/CVE-2022-42889.yaml name=crowdsecurity/CVE-2022-42889  
> time=“09-12-2022 20:48:24” level=info msg=“Adding trigger bucket” cfg=dry-water file=/etc/crowdsec/scenarios/CVE-2022-26134.yaml name=crowdsecurity/CVE-2022-26134  
> time=“09-12-2022 20:48:24” level=info msg=“Adding trigger bucket” cfg=small-brook file=/etc/crowdsec/scenarios/http-w00tw00t.yaml name=ltsich/http-w00tw00t  
> time=“09-12-2022 20:48:24” level=info msg=“Adding trigger bucket” cfg=nameless-water file=/etc/crowdsec/scenarios/CVE-2022-40684.yaml name=crowdsecurity/fortinet-cve-2022-40684  
> time=“09-12-2022 20:48:24” level=info msg=“Adding leaky bucket” cfg=lively-frog file=/etc/crowdsec/scenarios/http-crawl-non\_statics.yaml name=crowdsecurity/http-crawl-non\_statics  
> time=“09-12-2022 20:48:24” level=info msg=“Adding trigger bucket” cfg=snowy-pond file=/etc/crowdsec/scenarios/http-open-proxy.yaml name=crowdsecurity/http-open-proxy  
> time=“09-12-2022 20:48:24” level=warning msg=“Loaded 35 scenarios”  
> time=“09-12-2022 20:48:24” level=info msg=“loading acquisition file : /etc/crowdsec/acquis.yaml”  
> time=“09-12-2022 20:48:24” level=info msg=“Adding file /var/log/auth.log to datasources” type=file  
> time=“09-12-2022 20:48:24” level=info msg=“Adding file /var/log/mysql/error.log to datasources” type=file  
> time=“09-12-2022 20:48:24” level=info msg=“Adding file /var/log/syslog to datasources” type=file  
> time=“09-12-2022 20:48:24” level=info msg=“Adding file /var/log/kern.log to datasources” type=file  
> time=“09-12-2022 20:48:24” level=info msg=“Starting processing data”  
> time=“09-12-2022 20:48:24” level=info msg=“Running journalctl command: /usr/bin/journalctl [journalctl --follow -n 0 \_SYSTEMD\_UNIT=apache2.service]” src=“journalctl-\_SYSTEMD\_UNIT=apache2.service” type=journalctl

here is /var/log/auth.log

> Connection closed by authenticating user test 10.0.5.30 port 61027 [preauth]  
> Dec 9 20:50:08 localhost sshd[60108]: pam\_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=10.0.5.30 user=test  
> Dec 9 20:50:10 localhost sshd[60108]: Failed password for test from 10.0.5.30 port 61028 ssh2  
> Dec 9 20:50:19 localhost sshd[60108]: message repeated 2 times: [Failed password for test from 10.0.5.30 port 61028 ssh2]  
> Dec 9 20:50:20 localhost sshd[60108]: Connection closed by authenticating user test 10.0.5.30 port 61028 [preauth]  
> Dec 9 20:50:20 localhost sshd[60108]: PAM 2 more authentication failures; logname= uid=0 euid=0 tty=ssh ruser= rhost=10.0.5.30 user=test

---

_[View the full topic](https://discourse.crowdsec.net/t/crownsec-just-not-log-my-failed-attemps/1067)._
