# PostOverflow whitelists ONLY for specific scenarios

**URL:** <https://discourse.crowdsec.net/t/postoverflow-whitelists-only-for-specific-scenarios/2517>\
**Category:** crowdsec\
**Created:** [April 23, 2025, 3:38pm UTC](https://discourse.crowdsec.net/t/postoverflow-whitelists-only-for-specific-scenarios/2517 "2025-04-23T15:38:41Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![DuvelCorp](https://dub1.discourse-cdn.com/flex013/user_avatar/discourse.crowdsec.net/duvelcorp/32/529_2.png) [@DuvelCorp](https://discourse.crowdsec.net/u/DuvelCorp)\
**Post date:** [April 23, 2025, 3:38pm UTC](https://discourse.crowdsec.net/t/postoverflow-whitelists-only-for-specific-scenarios/2517/1 "2025-04-23T15:38:41Z")

</div>

Hi

Basically I have this to whitelist some ASN of my country

```auto
name: xxx/ASN-whitelist
description: "Whitelist Trusted Belgian ASNs"
#debug: true
whitelist:
  reason: "xxx Whitelisted Belgian ASN"
  expression:
    - evt.Meta.ASNumber in ['6848', '5432', '12392']
    - evt.Enriched.ASNumber in ['6848', '5432', '12392']

```

But this is too much for me.  
As I mostly only have false positive issues on my legit users with http-crawl-non\_statics scenario, and sometimes probing.  
And so I dont want to apply this ASN whitelist on all scenarios.

What I would like to do instead is a test like this in the whitelist expression:

```auto
SCENARIO in ['crowdsecurity/http-crawl-non_statics','crowdsecurity/http-probing'] 
AND 
evt.Enriched.ASNumber in ['6848', '5432', '12392']

```

I would prefer to not taint my scenarios files and so to do this in my custom s01-parse/whitelist file only.

Is it possible ?

Txs

---

<div class="post-metadata">

**Author:** ![isdnfan](https://dub1.discourse-cdn.com/flex013/user_avatar/discourse.crowdsec.net/isdnfan/32/1074_2.png) [@isdnfan](https://discourse.crowdsec.net/u/isdnfan)\
**Post date:** [May 26, 2025, 3:02pm UTC](https://discourse.crowdsec.net/t/postoverflow-whitelists-only-for-specific-scenarios/2517/2 "2025-05-26T15:02:20Z")

</div>

I’m seeing http-probing and non\_statics with legit users browsing Nextcloud (especially for image previews and avatars) so I ~~added~~ my custom application-related whitelist like this

> **cat ./crowdsec/\_my-nextcloud-whitelist.yml**
>
> ```auto
> name: _my/nextcloud-whitelist
> description: "Whitelist more events from Nextcloud"
> filter: "evt.Meta.service == 'http' && evt.Meta.log_type in ['http_access-log', 'http_error-log']"
> whitelist:
> reason: "my Nextcloud Whitelist"
> expression:
> - evt.Meta.http_status == '404' && evt.Meta.http_verb == 'POST' && evt.Meta.http_path == '/login/v2/poll' #device login
> - evt.Meta.http_status == '404' && evt.Meta.http_verb == 'GET' && evt.Meta.http_path == '/push/ws' #notify_push not running
> - evt.Meta.http_status == '404' && evt.Meta.http_verb == 'GET' && evt.Meta.http_path contains '/remote.php/dav/addressbooks/users/' && evt.Parsed.http_args contains 'photo' #addressbook
> - evt.Meta.http_status == '404' && evt.Meta.http_verb == 'HEAD' && evt.Meta.http_path contains '/remote.php/dav/files/' #HEAD while instant upload
> - evt.Meta.http_status == '404' && evt.Meta.http_verb == 'GET' && evt.Meta.http_path contains '/contacts/css/contacts-index.css' && evt.Parsed.http_args contains 'v'
> - evt.Meta.http_status == '404' && evt.Meta.http_verb == 'HEAD' && evt.Meta.http_path contains '/ocs/v2.php/apps/spreed/api/v1/(chat|room)' #Talk chats
> 
> ```

this allows you to ignore only specific events valid in your specific application and still block scanning bots

---

<div class="post-metadata">

**Author:** ![j0nny55555](https://dub1.discourse-cdn.com/flex013/user_avatar/discourse.crowdsec.net/j0nny55555/32/744_2.png) [@j0nny55555](https://discourse.crowdsec.net/u/j0nny55555)\
**Post date:** [March 17, 2026, 8:34pm UTC](https://discourse.crowdsec.net/t/postoverflow-whitelists-only-for-specific-scenarios/2517/3 "2026-03-17T20:34:52Z")

</div>

Thank you! This helped with making a filter for pf\_firewall drops

```auto
cat /etc/crowdsec/parsers/s02-enrich/pf-tcp-drop-allowlist.yaml
name: "_my/pf-tcp-allowlist"
description: "Allowlist specific tcp pf_drop port ranges"
filter: "evt.Meta.log_type == 'pf_drop' && evt.Meta.service == 'tcp'"
whitelist:
  reason: "Ignore drops on specific TCP port ranges"
  expression:
    # Port ranges to match
    - "int(evt.Parsed.dst_port) >= 1000 && int(evt.Parsed.dst_port) <= 2000"
    - "int(evt.Parsed.dst_port) == 3000"
    - "int(evt.Parsed.dst_port) >= 4000 && int(evt.Parsed.dst_port) <= 5000"

```
