Opnsense Crowdsec email notifications

Hi,

Im using crowdsec latest with opnsense latest, all is working well, and i have notifications to email, also working well, only that when i receive a notificatrion for ban ip due to portscan for example, i dont get which wan interface did that ban get on, i have 4 WAN interfaces and i want to know on which interface / WAN IP was that detceted on / banned on.

Thanks

Anyone? Any support is highly appreciated

Hey :waving_hand:

The parser set a meta attribute called iface if you inspect an alert via cscli alerts inspect <id> -d does that meta attribute include the information you are looking for?

to get the id you can run cscli alerts list and pick a portscan alert.

ref: hub/parsers/s01-parse/firewallservices/pf-logs.yaml at 19af1aa417466e5a819ea3b1683d4b4d08c1f15c · crowdsecurity/hub · GitHub