# Logs in Dominic-Wagner/vaultwarden collection are not getting parsed

**URL:** <https://discourse.crowdsec.net/t/logs-in-dominic-wagner-vaultwarden-collection-are-not-getting-parsed/1740>\
**Category:** Uncategorized\
**Created:** [April 3, 2024, 5:28pm UTC](https://discourse.crowdsec.net/t/logs-in-dominic-wagner-vaultwarden-collection-are-not-getting-parsed/1740 "2024-04-03T17:28:35Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![Skyfallgamer](https://avatars.discourse-cdn.com/v4/letter/s/e99b99/32.png) [@Skyfallgamer](https://discourse.crowdsec.net/u/Skyfallgamer)\
**Post date:** [April 3, 2024, 5:28pm UTC](https://discourse.crowdsec.net/t/logs-in-dominic-wagner-vaultwarden-collection-are-not-getting-parsed/1740/1 "2024-04-03T17:28:35Z")

</div>

Hello community  
I want to secure my vaultwarden with crowdsec because it’s awesome.  
I have already installed vaultwarden in docker and it’s alreasy logging like this:

cat /var/log/vaultwarden/vaultwarden.log

```auto
[2024-04-03 18:44:08.371][vaultwarden::api::identity][ERROR] Username or password is incorrect. Try again. IP: 185.16.53.93. Username: dfgdfgdf@gmail.com.
[2024-04-03 18:44:09.346][vaultwarden::api::identity][ERROR] Username or password is incorrect. Try again. IP: 185.16.53.93. Username: dfgdfgdf@gmail.com.
[2024-04-03 18:44:10.290][vaultwarden::api::identity][ERROR] Username or password is incorrect. Try again. IP: 185.16.53.93. Username: dfgdfgdf@gmail.com.

```

Looks great but crowdsec is doing nothing. The acquis.yaml looks like this

```auto
#Generated acquisition file - wizard.sh (service: ssh) / files : 
journalctl_filter:
 - _SYSTEMD_UNIT=ssh.service
labels:
  type: syslog
---
filenames:
 - /var/log/vaultwarden/vaultwarden.log
labels:
  type: Vaultwarden

```

cscli metris looks like this:

 ![image](https://europe1.discourse-cdn.com/flex013/uploads/crowdsec/original/1X/83400077e0004f9def3c554351f383a7a9e9a4e9.png)

I already tried to bruteforce myself but after 10 retries vaultwarden says

`[2024-04-03 18:44:18.027][vaultwarden::ratelimit][ERROR] Too many login requests`

But crowdsec is doing nothing ☹

```auto
root@Test:~# cscli decisions list
No active decisions

```

cscli explain

```
    ├ s00-raw
    | ├ 🔴 crowdsecurity/syslog-logs
    | └ 🟢 crowdsecurity/non-syslog (+5 ~8)
    ├ s01-parse
    | ├ 🔴 crowdsecurity/sshd-logs
    | └ 🟢 Dominic-Wagner/vaultwarden-logs (+11 ~2)
    ├ s02-enrich
    | ├ 🟢 crowdsecurity/dateparse-enrich (+2 ~2)
    | ├ 🟢 crowdsecurity/geoip-enrich (+13)
    | └ 🟢 crowdsecurity/whitelists (unchanged)
    ├-------- parser success 🟢
    ├ Scenarios
            ├ 🟢 Dominic-Wagner/vaultwarden-bf
            └ 🟢 Dominic-Wagner/vaultwarden-bf_user-enum

```

Any ideas what i am doing wrong?  
Thanks for your help!

---

<div class="post-metadata">

**Author:** ![iiAmLoz](https://dub1.discourse-cdn.com/flex013/user_avatar/discourse.crowdsec.net/iiamloz/32/386_2.png) [@iiAmLoz](https://discourse.crowdsec.net/u/iiAmLoz)\
**Post date:** [April 4, 2024, 8:04am UTC](https://discourse.crowdsec.net/t/logs-in-dominic-wagner-vaultwarden-collection-are-not-getting-parsed/1740/2 "2024-04-04T08:04:44Z")

</div>

Most likely the parsing is working as shown by the explain. Your just properly just slow to trigger it manually by typing the scenario tries to detect automated bruteforce attempts.

Vaultwarden has implement a self brute force detection which is not parsed by us, you can lower the capacity of the scenario to see if it improves detection by manually typing.

---

<div class="post-metadata">

**Author:** ![Skyfallgamer](https://avatars.discourse-cdn.com/v4/letter/s/e99b99/32.png) [@Skyfallgamer](https://discourse.crowdsec.net/u/Skyfallgamer)\
**Post date:** [April 4, 2024, 8:19am UTC](https://discourse.crowdsec.net/t/logs-in-dominic-wagner-vaultwarden-collection-are-not-getting-parsed/1740/3 "2024-04-04T08:19:07Z")

</div>

Thank you for your answer.  
How can I test if my crowdsec is protecting vaultwarden than?  
I already use crowdsec with authelia and there manual triggering worked fine for testing.

---

<div class="post-metadata">

**Author:** ![iiAmLoz](https://dub1.discourse-cdn.com/flex013/user_avatar/discourse.crowdsec.net/iiamloz/32/386_2.png) [@iiAmLoz](https://discourse.crowdsec.net/u/iiAmLoz)\
**Post date:** [April 4, 2024, 8:22am UTC](https://discourse.crowdsec.net/t/logs-in-dominic-wagner-vaultwarden-collection-are-not-getting-parsed/1740/4 "2024-04-04T08:22:36Z")

</div>

> [@Skyfallgamer](#):
>
> How can I test if my crowdsec is protecting vaultwarden than?

Well the logs are already being monitored, how are you exposing vaultwarden to the internet?

---

<div class="post-metadata">

**Author:** ![Skyfallgamer](https://avatars.discourse-cdn.com/v4/letter/s/e99b99/32.png) [@Skyfallgamer](https://discourse.crowdsec.net/u/Skyfallgamer)\
**Post date:** [April 4, 2024, 8:25am UTC](https://discourse.crowdsec.net/t/logs-in-dominic-wagner-vaultwarden-collection-are-not-getting-parsed/1740/5 "2024-04-04T08:25:07Z")

</div>

I am exposing vaultwarden over a nginx proxy manager.

---

<div class="post-metadata">

**Author:** ![iiAmLoz](https://dub1.discourse-cdn.com/flex013/user_avatar/discourse.crowdsec.net/iiamloz/32/386_2.png) [@iiAmLoz](https://discourse.crowdsec.net/u/iiAmLoz)\
**Post date:** [April 4, 2024, 8:26am UTC](https://discourse.crowdsec.net/t/logs-in-dominic-wagner-vaultwarden-collection-are-not-getting-parsed/1740/6 "2024-04-04T08:26:25Z")

</div>

Then you would either need to use a custom implementation of nginx proxy manager with our remediation component or use the firewall remediation but if you use something like cloudflare then the former is the way to go

---

<div class="post-metadata">

**Author:** ![Skyfallgamer](https://avatars.discourse-cdn.com/v4/letter/s/e99b99/32.png) [@Skyfallgamer](https://discourse.crowdsec.net/u/Skyfallgamer)\
**Post date:** [April 4, 2024, 8:32am UTC](https://discourse.crowdsec.net/t/logs-in-dominic-wagner-vaultwarden-collection-are-not-getting-parsed/1740/7 "2024-04-04T08:32:19Z")

</div>

My idea was to install the bouncer on the nginx proxy virtual machine. On the other virtual machines crowdsec should parse the logs and send to the nginx crowdsec to block the ip before the proxy forwards them. Is this the right way i am trying? Or are you meaning something different?

---

<div class="post-metadata">

**Author:** ![iiAmLoz](https://dub1.discourse-cdn.com/flex013/user_avatar/discourse.crowdsec.net/iiamloz/32/386_2.png) [@iiAmLoz](https://discourse.crowdsec.net/u/iiAmLoz)\
**Post date:** [April 4, 2024, 8:35am UTC](https://discourse.crowdsec.net/t/logs-in-dominic-wagner-vaultwarden-collection-are-not-getting-parsed/1740/8 "2024-04-04T08:35:40Z")

</div>

Yes that is correct but the official nginx proxy manager does not support CrowdSec

---

<div class="post-metadata">

**Author:** ![Skyfallgamer](https://avatars.discourse-cdn.com/v4/letter/s/e99b99/32.png) [@Skyfallgamer](https://discourse.crowdsec.net/u/Skyfallgamer)\
**Post date:** [April 4, 2024, 8:39am UTC](https://discourse.crowdsec.net/t/logs-in-dominic-wagner-vaultwarden-collection-are-not-getting-parsed/1740/9 "2024-04-04T08:39:00Z")

</div>

Ok but is the proxy the reason why crowdsec is not detecting ah bruteforce at my vaultwarden?  
If manual trigger is to slow how can I test my configuration?

---

<div class="post-metadata">

**Author:** ![iiAmLoz](https://dub1.discourse-cdn.com/flex013/user_avatar/discourse.crowdsec.net/iiamloz/32/386_2.png) [@iiAmLoz](https://discourse.crowdsec.net/u/iiAmLoz)\
**Post date:** [April 4, 2024, 8:42am UTC](https://discourse.crowdsec.net/t/logs-in-dominic-wagner-vaultwarden-collection-are-not-getting-parsed/1740/10 "2024-04-04T08:42:30Z")

</div>

> [@Skyfallgamer](#):
>
> Ok but is the proxy the reason why crowdsec is not detecting ah bruteforce at my vaultwarden?

No, the proxy just wont enforce decision that are made, the parsing is working just either your too slow to manually trigger it OR vault warden has it own defensives which stops us from hitting the threshold as vaultwarden is lower than ours

You can add your ip via `cscli decisions add --ip <your_wan>` but most likely your setup wont do anything because you dont have any remediation components [Introduction | CrowdSec](https://docs.crowdsec.net/u/bouncers/intro)

---

<div class="post-metadata">

**Author:** ![Skyfallgamer](https://avatars.discourse-cdn.com/v4/letter/s/e99b99/32.png) [@Skyfallgamer](https://discourse.crowdsec.net/u/Skyfallgamer)\
**Post date:** [April 4, 2024, 10:37am UTC](https://discourse.crowdsec.net/t/logs-in-dominic-wagner-vaultwarden-collection-are-not-getting-parsed/1740/11 "2024-04-04T10:37:25Z")

</div>

Oh yeah i tried a bruteforce with some code and it worked 🙂

 ![image](https://europe1.discourse-cdn.com/flex013/uploads/crowdsec/original/1X/a45fa83f35384fc34f7103f1a94a2322586ab9f4.png)

Thank you very much 🙂
