Hello,
I am trying to whitelist the following key/value pair:
{
"key": "ASNOrg",
"value": "XXX"
},
I have added the following at /etc/crowdsec/postoverflows/s01-whitelist/whitelist-xxx.yaml
name: user/whitelist-xxx
description: Whitelist XXX
whitelist:
reason: Whitelisted because XXX
expression:
- evt.Enriched.ASNOrg == 'XXX'
I made 100% sure I restarted the Crowdsec docker container, and I do see this:
cscli postoverflows list
POSTOVERFLOWS
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
Name π¦ Status Version Local Path
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
user/whitelist-xxx π enabled,local /etc/crowdsec/postoverflows/s01-whitelist/whitelist-xxx.yaml
However, I am still banning clients with that same ASNOrg value. Would appreciate any help!