Important Information
This post has been marked as resolved. If this is a mistake please press the red button below or type /unresolve
1 messages · Page 1 of 1 (latest)
This post has been marked as resolved. If this is a mistake please press the red button below or type /unresolve
This is handled by crowdsecurity/whitelists parser which is installed by default, you can remove the parser by running
cscli parsers remove crowdsecurity/whitelists
https://app.crowdsec.net/hub/author/crowdsecurity/log-parsers/whitelists
Can that be edited to only whitelist certain ips?
Also thanks for the quick reply :)
parsers list doesn't seem to show that for me
Yes but that'll taint it which will make it ineligible for automatic updates. I recommend creating your own for anything custom.
The command I gave you should have removed it, you can reload CrowdSec after to apply the change
Weird it gives nothing to install or remove I guess it was never enabled? Strange that CrowdSec isnt picking up a portscan or bruteforce attempt then
It does detect and block outside scans but internals are a no show
Resolving Any way to make CrowdSec monitor private ips?