# Whitelist by ASNNumber

**URL:** <https://discourse.crowdsec.net/t/whitelist-by-asnnumber/539>\
**Category:** crowdsec\
**Created:** [January 17, 2022, 1:54pm UTC](https://discourse.crowdsec.net/t/whitelist-by-asnnumber/539 "2022-01-17T13:54:31Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![eguaj](https://dub1.discourse-cdn.com/flex013/user_avatar/discourse.crowdsec.net/eguaj/32/262_2.png) [@eguaj](https://discourse.crowdsec.net/u/eguaj)\
**Post date:** [January 17, 2022, 1:54pm UTC](https://discourse.crowdsec.net/t/whitelist-by-asnnumber/539/1 "2022-01-17T13:54:31Z")

</div>

Hi,

I’m having a hard time figuring out how to whitelist events from specific ASNNumber.

I created a postoverflow whitelist in `/etc/crowdsec/postoverflows/s01-whitelist/zz-whitelist-AS.yaml` and tried various expressions without success.

Here are the ones that pass the compilation, but the `ASNumber` seems to be empty at runtime:

```auto
name: zz-whitelist-AS
description: Whitelist some AS
debug: true
whitelist:
  reason: Whitelisted AS
  expression:
    - evt.Enriched.ASNNumber in [3215, 15557, 12322, 5410] 
    - evt.Meta.ASNNumber in [3215, 15557, 12322, 5410]
    - evt.Overflow.Sources.AsNumber in [3215, 15557, 12322, 5410]

```

Here is the debug output from theses expressions:

- `evt.Enriched.ASNumber` → `level=debug msg=" evt.Enriched.ASNNumber = ''" `
- `evt.Meta.ASNNumber` → `msg=" evt.Meta.ASNNumber = ''" `
- `evt.Overflow.Sources.AsNumber` → `msg=" evt.Overflow.Sources.AsNumber = '{ 0 0 <nil> <nil>}'" `

Is it possible to whitelist events based on `ASNNumber`?

Thanks.

---

<div class="post-metadata">

**Author:** ![alteredCoder](https://dub1.discourse-cdn.com/flex013/user_avatar/discourse.crowdsec.net/alteredcoder/32/44_2.png) [@alteredCoder](https://discourse.crowdsec.net/u/alteredCoder)\
**Post date:** [January 18, 2022, 2:03pm UTC](https://discourse.crowdsec.net/t/whitelist-by-asnnumber/539/2 "2022-01-18T14:03:44Z")

</div>

Hello @eguaj ,

You can do it by accessing the AS Number in postoverflow in `evt.Overflow.Alert.Source.AsNumber` .

Hope it helps!

---

<div class="post-metadata">

**Author:** ![eguaj](https://dub1.discourse-cdn.com/flex013/user_avatar/discourse.crowdsec.net/eguaj/32/262_2.png) [@eguaj](https://discourse.crowdsec.net/u/eguaj)\
**Post date:** [January 18, 2022, 5:30pm UTC](https://discourse.crowdsec.net/t/whitelist-by-asnnumber/539/3 "2022-01-18T17:30:39Z")

</div>

Thank you, it works!

I also had to change the AS numbers to strings (i.e. `'3215' instead of `3215`):

```auto
name: zz-whitelist-AS
description: Whitelist some AS
debug: true
whitelist:
  reason: Whitelisted AS
  expression:
    - evt.Overflow.Alert.Source.AsNumber in ['3215', '15557', '12322', '5410']

```

---

<div class="post-metadata">

**Author:** ![j0nny55555](https://dub1.discourse-cdn.com/flex013/user_avatar/discourse.crowdsec.net/j0nny55555/32/744_2.png) [@j0nny55555](https://discourse.crowdsec.net/u/j0nny55555)\
**Post date:** [February 21, 2024, 7:07am UTC](https://discourse.crowdsec.net/t/whitelist-by-asnnumber/539/4 "2024-02-21T07:07:32Z")

</div>

Just wanted to thank you both for the notes and wanted to share that while I was able to make a version like this for ‘postoverflows’, it wasn’t until I made a ‘parsers’ detail that I saw explain show a ‘whitelisted’ response.

Suggested file name: /etc/crowdsec/parsers/s02-enrich/zz-whitelist.yml  
File contents (ASN numbers are fake - verify what you use!):

```auto
name: homelab/ASN-whitelist
description: "Whitelist Trusted ASNs"
#debug: true
whitelist:
  reason: "Whitelisted ASN"
  expression:
    - evt.Meta.ASNumber in ['1010', '10101', '101']
    - evt.Enriched.ASNumber in ['1010', '10101', '101']

```
