Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- ime="2024-05-13T13:29:12+01:00" level=info msg="Loaded 1 parser nodes" file=/etc/crowdsec/parsers/s02-enrich/http-logs.yaml stage=s02-enrich
- time="2024-05-13T13:29:12+01:00" level=info msg="Loaded 1 parser nodes" file=/etc/crowdsec/parsers/s02-enrich/whitelists.yaml stage=s02-enrich
- time="2024-05-13T13:29:12+01:00" level=info msg="Loaded 11 nodes from 3 stages"
- time="2024-05-13T13:29:12+01:00" level=info msg="No postoverflow parsers to load"
- time="2024-05-13T13:29:12+01:00" level=info msg="Loading 44 scenario files"
- time="2024-05-13T13:29:12+01:00" level=info msg="Adding trigger bucket" cfg=broken-darkness name=crowdsecurity/netgear_rce
- time="2024-05-13T13:29:12+01:00" level=info msg="Adding trigger bucket" cfg=young-wood name=crowdsecurity/vmware-vcenter-vmsa-2021-0027
- time="2024-05-13T13:29:12+01:00" level=info msg="Adding trigger bucket" cfg=dry-pond name=crowdsecurity/apache_log4j2_cve-2021-44228
- time="2024-05-13T13:29:12+01:00" level=info msg="Adding trigger bucket" cfg=cool-leaf name=crowdsecurity/fortinet-cve-2018-13379
- time="2024-05-13T13:29:12+01:00" level=info msg="Adding leaky bucket" cfg=delicate-cloud name=crowdsecurity/ssh-slow-bf
- time="2024-05-13T13:29:12+01:00" level=info msg="Adding leaky bucket" cfg=purple-violet name=crowdsecurity/ssh-slow-bf_user-enum
- time="2024-05-13T13:29:12+01:00" level=info msg="Adding trigger bucket" cfg=lingering-dream name=crowdsecurity/CVE-2022-26134
- time="2024-05-13T13:29:12+01:00" level=info msg="Adding leaky bucket" cfg=patient-firefly name=crowdsecurity/http-bad-user-agent
- time="2024-05-13T13:29:12+01:00" level=info msg="Adding trigger bucket" cfg=ancient-flower name=crowdsecurity/CVE-2023-22518
- time="2024-05-13T13:29:12+01:00" level=info msg="Adding leaky bucket" cfg=billowing-mountain name=crowdsecurity/CVE-2022-41697
- time="2024-05-13T13:29:12+01:00" level=info msg="Adding trigger bucket" cfg=old-water name=crowdsecurity/http-cve-2021-41773
- time="2024-05-13T13:29:12+01:00" level=info msg="Adding leaky bucket" cfg=white-dew name=crowdsecurity/ssh-bf
- time="2024-05-13T13:29:12+01:00" level=info msg="Adding leaky bucket" cfg=damp-brook name=crowdsecurity/ssh-bf_user-enum
- time="2024-05-13T13:29:12+01:00" level=info msg="Adding trigger bucket" cfg=aged-haze name=crowdsecurity/CVE-2017-9841
- time="2024-05-13T13:29:12+01:00" level=info msg="Adding trigger bucket" cfg=dark-frog name=crowdsecurity/CVE-2022-41082
- time="2024-05-13T13:29:12+01:00" level=info msg="Adding leaky bucket" cfg=weathered-sky name=crowdsecurity/http-xss-probbing
- time="2024-05-13T13:29:12+01:00" level=info msg="Adding leaky bucket" cfg=white-sky name=crowdsecurity/http-sqli-probbing-detection
- time="2024-05-13T13:29:12+01:00" level=info msg="Adding trigger bucket" cfg=morning-morning name=crowdsecurity/CVE-2022-44877
- time="2024-05-13T13:29:12+01:00" level=info msg="Adding trigger bucket" cfg=dawn-bird name=crowdsecurity/spring4shell_cve-2022-22965
- time="2024-05-13T13:29:12+01:00" level=info msg="Adding leaky bucket" cfg=bitter-voice name=crowdsecurity/http-sensitive-files
- time="2024-05-13T13:29:12+01:00" level=info msg="Adding leaky bucket" cfg=falling-breeze name=crowdsecurity/http-admin-interface-probing
- time="2024-05-13T13:29:12+01:00" level=info msg="Adding trigger bucket" cfg=young-frost name=crowdsecurity/thinkphp-cve-2018-20062
- time="2024-05-13T13:29:12+01:00" level=info msg="Adding trigger bucket" cfg=lively-sky name=ltsich/http-w00tw00t
- time="2024-05-13T13:29:12+01:00" level=info msg="Adding leaky bucket" cfg=divine-shadow name=crowdsecurity/http-cve-probing
- time="2024-05-13T13:29:12+01:00" level=info msg="Adding leaky bucket" cfg=delicate-pond name=crowdsecurity/http-probing
- time="2024-05-13T13:29:12+01:00" level=info msg="Adding leaky bucket" cfg=solitary-hill name=crowdsecurity/http-path-traversal-probing
- time="2024-05-13T13:29:12+01:00" level=info msg="Adding trigger bucket" cfg=icy-pine name=crowdsecurity/CVE-2022-37042
- time="2024-05-13T13:29:12+01:00" level=info msg="Adding leaky bucket" cfg=falling-firefly name=crowdsecurity/http-backdoors-attempts
- time="2024-05-13T13:29:12+01:00" level=info msg="Adding trigger bucket" cfg=dawn-paper name=crowdsecurity/f5-big-ip-cve-2020-5902
- time="2024-05-13T13:29:12+01:00" level=info msg="Adding trigger bucket" cfg=blue-water name=crowdsecurity/http-open-proxy
- time="2024-05-13T13:29:12+01:00" level=info msg="Adding leaky bucket" cfg=weathered-dust name=crowdsecurity/http-crawl-non_statics
- time="2024-05-13T13:29:12+01:00" level=info msg="Adding trigger bucket" cfg=floral-frog name=crowdsecurity/CVE-2022-35914
- time="2024-05-13T13:29:12+01:00" level=info msg="Adding trigger bucket" cfg=withered-wave name=crowdsecurity/CVE-2023-22515
- time="2024-05-13T13:29:12+01:00" level=info msg="Adding trigger bucket" cfg=icy-sun name=crowdsecurity/pulse-secure-sslvpn-cve-2019-11510
- time="2024-05-13T13:29:12+01:00" level=info msg="Adding trigger bucket" cfg=late-silence name=crowdsecurity/vmware-cve-2022-22954
- time="2024-05-13T13:29:12+01:00" level=info msg="Adding trigger bucket" cfg=summer-pine name=crowdsecurity/http-cve-2021-42013
- time="2024-05-13T13:29:12+01:00" level=info msg="Adding leaky bucket" cfg=shy-dew name=crowdsecurity/CVE-2022-46169-bf
- time="2024-05-13T13:29:12+01:00" level=info msg="Adding trigger bucket" cfg=ancient-brook name=crowdsecurity/CVE-2022-46169-cmd
- time="2024-05-13T13:29:12+01:00" level=info msg="Adding leaky bucket" cfg=holy-hill name=crowdsecurity/http-wordpress-scan
- time="2024-05-13T13:29:12+01:00" level=info msg="Adding trigger bucket" cfg=bitter-silence name=crowdsecurity/jira_cve-2021-26086
- time="2024-05-13T13:29:12+01:00" level=info msg="Adding trigger bucket" cfg=floral-snowflake name=crowdsecurity/CVE-2023-49103
- time="2024-05-13T13:29:12+01:00" level=info msg="Adding trigger bucket" cfg=proud-frost name=crowdsecurity/grafana-cve-2021-43798
- time="2024-05-13T13:29:12+01:00" level=info msg="Adding leaky bucket" cfg=late-silence name=crowdsecurity/http-generic-bf
- time="2024-05-13T13:29:12+01:00" level=info msg="Adding leaky bucket" cfg=twilight-sky name=LePresidente/http-generic-401-bf
- time="2024-05-13T13:29:12+01:00" level=info msg="Adding leaky bucket" cfg=red-snow name=LePresidente/http-generic-403-bf
- time="2024-05-13T13:29:12+01:00" level=info msg="Adding trigger bucket" cfg=small-sea name=crowdsecurity/CVE-2022-42889
- time="2024-05-13T13:29:12+01:00" level=info msg="Adding trigger bucket" cfg=young-moon name=crowdsecurity/fortinet-cve-2022-40684
- time="2024-05-13T13:29:12+01:00" level=info msg="Adding trigger bucket" cfg=icy-frost name=crowdsecurity/CVE-2019-18935
- time="2024-05-13T13:29:12+01:00" level=info msg="Adding leaky bucket" cfg=withered-dream name=firix/authentik-bf
- time="2024-05-13T13:29:12+01:00" level=info msg="Adding leaky bucket" cfg=twilight-dust name=firix/authentik-bf_user-enum
- time="2024-05-13T13:29:12+01:00" level=info msg="Loaded 50 scenarios"
- time="2024-05-13T13:29:12+01:00" level=info msg="loading acquisition file : /etc/crowdsec/acquis.yaml"
- time="2024-05-13T13:29:12+01:00" level=warning msg="No matching files for pattern /var/log/crowdsec/traefik.log" type=file
- time="2024-05-13T13:29:12+01:00" level=info msg="Adding file /var/log/auth.log to datasources" type=file
- time="2024-05-13T13:29:12+01:00" level=info msg="127.0.0.1 - [Mon, 13 May 2024 13:29:12 BST] \"POST /v1/watchers/login HTTP/1.1 200 59.390698ms \"crowdsec/v1.6.1-c6e40191\" \""
- time="2024-05-13T13:29:12+01:00" level=info msg="Starting processing data"
- time="2024-05-13T13:29:12+01:00" level=info msg="Starting docker acquisition" type=docker
- time="2024-05-13T13:29:12+01:00" level=info msg="Container watcher started, interval: 1s" type=docker
- time="2024-05-13T13:29:12+01:00" level=info msg="DockerSource Manager started" type=docker
- time="2024-05-13T13:29:13+01:00" level=info msg="start tail for container authentik-server" container_name=authentik-server type=docker
- time="2024-05-13T13:30:12+01:00" level=info msg="127.0.0.1 - [Mon, 13 May 2024 13:30:12 BST] \"GET /v1/heartbeat HTTP/1.1 200 2.274665ms \"crowdsec/v1.6.1-c6e40191\" \""
- time="2024-05-13T13:31:12+01:00" level=info msg="127.0.0.1 - [Mon, 13 May 2024 13:31:12 BST] \"GET /v1/heartbeat HTTP/1.1 200 2.214872ms \"crowdsec/v1.6.1-c6e40191\" \""
- time="2024-05-13T13:32:12+01:00" level=info msg="127.0.0.1 - [Mon, 13 May 2024 13:32:12 BST] \"GET /v1/heartbeat HTTP/1.1 200 2.318618ms \"crowdsec/v1.6.1-c6e40191\" \""
- time="2024-05-13T13:33:12+01:00" level=info msg="127.0.0.1 - [Mon, 13 May 2024 13:33:12 BST] \"GET /v1/heartbeat HTTP/1.1 200 2.158108ms \"crowdsec/v1.6.1-c6e40191\" \""
- time="2024-05-13T13:34:12+01:00" level=info msg="127.0.0.1 - [Mon, 13 May 2024 13:34:12 BST] \"GET /v1/heartbeat HTTP/1.1 200 3.265237ms \"crowdsec/v1.6.1-c6e40191\" \""
- time="2024-05-13T13:35:12+01:00" level=info msg="127.0.0.1 - [Mon, 13 May 2024 13:35:12 BST] \"GET /v1/heartbeat HTTP/1.1 200 3.119759ms \"crowdsec/v1.6.1-c6e40191\" \""
- time="2024-05-13T13:36:12+01:00" level=info msg="127.0.0.1 - [Mon, 13 May 2024 13:36:12 BST] \"GET /v1/heartbeat HTTP/1.1 200 2.45724ms \"crowdsec/v1.6.1-c6e40191\" \""
- time="2024-05-13T13:37:12+01:00" level=info msg="127.0.0.1 - [Mon, 13 May 2024 13:37:12 BST] \"GET /v1/heartbeat HTTP/1.1 200 3.0445ms \"crowdsec/v1.6.1-c6e40191\" \""
- time="2024-05-13T13:38:12+01:00" level=info msg="127.0.0.1 - [Mon, 13 May 2024 13:38:12 BST] \"GET /v1/heartbeat HTTP/1.1 200 2.1567ms \"crowdsec/v1.6.1-c6e40191\" \""
- time="2024-05-13T13:39:12+01:00" level=info msg="127.0.0.1 - [Mon, 13 May 2024 13:39:12 BST] \"GET /v1/heartbeat HTTP/1.1 200 2.188359ms \"crowdsec/v1.6.1-c6e40191\" \""
- time="2024-05-13T13:40:12+01:00" level=info msg="127.0.0.1 - [Mon, 13 May 2024 13:40:12 BST] \"GET /v1/heartbeat HTTP/1.1 200 2.353497ms \"crowdsec/v1.6.1-c6e40191\" \""
- time="2024-05-13T13:41:12+01:00" level=info msg="127.0.0.1 - [Mon, 13 May 2024 13:41:12 BST] \"GET /v1/heartbeat HTTP/1.1 200 2.397497ms \"crowdsec/v1.6.1-c6e40191\" \""
- time="2024-05-13T13:42:12+01:00" level=info msg="127.0.0.1 - [Mon, 13 May 2024 13:42:12 BST] \"GET /v1/heartbeat HTTP/1.1 200 2.905138ms \"crowdsec/v1.6.1-c6e40191\" \""
- time="2024-05-13T13:43:12+01:00" level=info msg="127.0.0.1 - [Mon, 13 May 2024 13:43:12 BST] \"GET /v1/heartbeat HTTP/1.1 200 2.875858ms \"crowdsec/v1.6.1-c6e40191\" \""
- time="2024-05-13T13:44:12+01:00" level=info msg="127.0.0.1 - [Mon, 13 May 2024 13:44:12 BST] \"GET /v1/heartbeat HTTP/1.1 200 2.017824ms \"crowdsec/v1.6.1-c6e40191\" \""
- time="2024-05-13T13:45:12+01:00" level=info msg="127.0.0.1 - [Mon, 13 May 2024 13:45:12 BST] \"GET /v1/heartbeat HTTP/1.1 200 3.484719ms \"crowdsec/v1.6.1-c6e40191\" \""
- time="2024-05-13T13:46:12+01:00" level=info msg="127.0.0.1 - [Mon, 13 May 2024 13:46:12 BST] \"GET /v1/heartbeat HTTP/1.1 200 2.393727ms \"crowdsec/v1.6.1-c6e40191\" \""
- time="2024-05-13T13:47:12+01:00" level=info msg="127.0.0.1 - [Mon, 13 May 2024 13:47:12 BST] \"GET /v1/heartbeat HTTP/1.1 200 2.19337ms \"crowdsec/v1.6.1-c6e40191\" \""
- time="2024-05-13T13:47:31+01:00" level=info msg="capi metrics: sending"
- time="2024-05-13T13:48:12+01:00" level=info msg="127.0.0.1 - [Mon, 13 May 2024 13:48:12 BST] \"GET /v1/heartbeat HTTP/1.1 200 2.09189ms \"crowdsec/v1.6.1-c6e40191\" \""
- time="2024-05-13T13:49:12+01:00" level=info msg="127.0.0.1 - [Mon, 13 May 2024 13:49:12 BST] \"GET /v1/heartbeat HTTP/1.1 200 2.953876ms \"crowdsec/v1.6.1-c6e40191\" \""
- time="2024-05-13T13:50:12+01:00" level=info msg="127.0.0.1 - [Mon, 13 May 2024 13:50:12 BST] \"GET /v1/heartbeat HTTP/1.1 200 2.17129ms \"crowdsec/v1.6.1-c6e40191\" \""
- time="2024-05-13T13:51:12+01:00" level=info msg="127.0.0.1 - [Mon, 13 May 2024 13:51:12 BST] \"GET /v1/heartbeat HTTP/1.1 200 2.245062ms \"crowdsec/v1.6.1-c6e40191\" \""
- time="2024-05-13T13:52:12+01:00" level=info msg="127.0.0.1 - [Mon, 13 May 2024 13:52:12 BST] \"GET /v1/heartbeat HTTP/1.1 200 2.681697ms \"crowdsec/v1.6.1-c6e40191\" \""
- time="2024-05-13T13:53:12+01:00" level=info msg="127.0.0.1 - [Mon, 13 May 2024 13:53:12 BST] \"GET /v1/heartbeat HTTP/1.1 200 2.686108ms \"crowdsec/v1.6.1-c6e40191\" \""
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement