|
|
|
|
|
by klausagnoletti
1307 days ago
|
|
Hey, head of community at CrowdSec here. Could you elaborate on your situation and the 'opaque' replies from the agent you're receiving in a mail to klaus at crowdsec dot net? Very interested in understanding your issues and hopefully help you to build trust :-) |
|
The main issue is that on my hosts where fail2ban are running, I see week on week activity and banned hosts.
When I look into cscli decisions or cscli metrics, it gives me the indication that nothing is happening which I don't believe is true. Maybe it is doing the work it promises, but I can't easily see it.
This could be a false negative, and that there genuinely is less malicious connection attempts. The busy fail2ban are bastion hosts on AWS, while the others are hosted on DigitalOcean. For me as a user though, I wish there was a way to see historically blocked hosts. The last time I looked half a year ago, this was not available in CrowdSec.