Security Engine: no activity on OPNsense

Hi–

New user here…have installed Crowdsec on OPNsense as a plugin. It seems to be configured correctly, but I’m getting a persistent “Security Engine - no activity” error:

Security Engine No Alerts

The Engine No Alerts issue appears when your Security Engine has been running but hasn’t forwarded any alerts to the Central API in the last 48 hours.

I’ve gone through the “fix” instructions (multiple times) as well as online searches in order to remediate this, but no matter what I do, I still have this error.

I’m now completely stuck - I’m running 26.1.1 (had to upgrade as part of this process) but OPNsense is only using Crowdsec 1.7.4 (and 1.7.6 is available) but I understand that upgrade will be handled by OPNsense when it’s available.

Would appreciate any help…I’m (of course) a bit of a noob, but happy to upload any logs, etc. that may be helpful.

Thanks!

What services do you expose either via OPNsense (reverse proxy or firewall) to services you host within the opnsense LAN?

Right now, none–but I do expect that to change in the near future. Am I hearing you say the error is simply due to no open services?

Exactly that, crowdsec defends exposed services since you don’t currently have any its normal you don’t have any alerts.