Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Check if lapi needs to register an additional agent
- sqlite database permissions updated
- time="25-08-2023 09:55:29" level=info msg="hub index is up to date"
- time="25-08-2023 09:55:29" level=info msg="Wrote new 812062 bytes index to /etc/crowdsec/hub/.index.json"
- time="25-08-2023 09:55:29" level=info msg="dependency of crowdsecurity/sshd : outdated parsers crowdsecurity/sshd-logs"
- time="25-08-2023 09:55:29" level=info msg="dependency of crowdsecurity/linux : sub collection crowdsecurity/sshd is broken : outdated parsers crowdsecurity/sshd-logs"
- Running: cscli collections upgrade "crowdsecurity/linux"
- time="25-08-2023 09:55:30" level=info msg="crowdsecurity/linux : up-to-date"
- time="25-08-2023 09:55:30" level=info msg="Item 'crowdsecurity/linux' is up-to-date"
- time="25-08-2023 09:55:30" level=info msg="Run 'sudo systemctl reload crowdsec' for the new configuration to be effective."
- Running: cscli parsers upgrade "crowdsecurity/whitelists"
- time="25-08-2023 09:55:31" level=info msg="crowdsecurity/whitelists : up-to-date"
- time="25-08-2023 09:55:31" level=info msg="Item 'crowdsecurity/whitelists' is up-to-date"
- time="25-08-2023 09:55:31" level=info msg="Run 'sudo systemctl reload crowdsec' for the new configuration to be effective."
- Running: cscli parsers install "crowdsecurity/docker-logs"
- time="25-08-2023 09:55:33" level=warning msg="crowdsecurity/docker-logs : overwrite"
- time="25-08-2023 09:55:33" level=info msg="Enabled crowdsecurity/docker-logs"
- time="25-08-2023 09:55:33" level=info msg="Run 'sudo systemctl reload crowdsec' for the new configuration to be effective."
- Running: cscli parsers install "crowdsecurity/cri-logs"
- time="25-08-2023 09:55:34" level=warning msg="crowdsecurity/cri-logs : overwrite"
- time="25-08-2023 09:55:34" level=info msg="Enabled crowdsecurity/cri-logs"
- time="25-08-2023 09:55:34" level=info msg="Run 'sudo systemctl reload crowdsec' for the new configuration to be effective."
- Running: cscli collections install "crowdsecurity/nginx"
- time="25-08-2023 09:55:35" level=warning msg="crowdsecurity/nginx-logs : overwrite"
- time="25-08-2023 09:55:35" level=warning msg="crowdsecurity/nginx-req-limit-exceeded : overwrite"
- time="25-08-2023 09:55:35" level=warning msg="crowdsecurity/http-logs : overwrite"
- time="25-08-2023 09:55:36" level=warning msg="crowdsecurity/http-crawl-non_statics : overwrite"
- time="25-08-2023 09:55:36" level=warning msg="crowdsecurity/http-probing : overwrite"
- time="25-08-2023 09:55:36" level=warning msg="crowdsecurity/http-bad-user-agent : overwrite"
- time="25-08-2023 09:55:36" level=warning msg="crowdsecurity/http-path-traversal-probing : overwrite"
- time="25-08-2023 09:55:36" level=warning msg="crowdsecurity/http-sensitive-files : overwrite"
- time="25-08-2023 09:55:36" level=warning msg="crowdsecurity/http-sqli-probing : overwrite"
- time="25-08-2023 09:55:36" level=warning msg="crowdsecurity/http-xss-probing : overwrite"
- time="25-08-2023 09:55:36" level=warning msg="crowdsecurity/http-backdoors-attempts : overwrite"
- time="25-08-2023 09:55:36" level=warning msg="ltsich/http-w00tw00t : overwrite"
- time="25-08-2023 09:55:36" level=warning msg="crowdsecurity/http-generic-bf : overwrite"
- time="25-08-2023 09:55:36" level=warning msg="crowdsecurity/http-open-proxy : overwrite"
- time="25-08-2023 09:55:36" level=warning msg="crowdsecurity/http-cve-2021-41773 : overwrite"
- time="25-08-2023 09:55:36" level=warning msg="crowdsecurity/http-cve-2021-42013 : overwrite"
- time="25-08-2023 09:55:36" level=warning msg="crowdsecurity/grafana-cve-2021-43798 : overwrite"
- time="25-08-2023 09:55:36" level=warning msg="crowdsecurity/vmware-vcenter-vmsa-2021-0027 : overwrite"
- time="25-08-2023 09:55:36" level=warning msg="crowdsecurity/fortinet-cve-2018-13379 : overwrite"
- time="25-08-2023 09:55:36" level=warning msg="crowdsecurity/pulse-secure-sslvpn-cve-2019-11510 : overwrite"
- time="25-08-2023 09:55:36" level=warning msg="crowdsecurity/f5-big-ip-cve-2020-5902 : overwrite"
- time="25-08-2023 09:55:36" level=warning msg="crowdsecurity/thinkphp-cve-2018-20062 : overwrite"
- time="25-08-2023 09:55:36" level=warning msg="crowdsecurity/apache_log4j2_cve-2021-44228 : overwrite"
- time="25-08-2023 09:55:36" level=warning msg="crowdsecurity/jira_cve-2021-26086 : overwrite"
- time="25-08-2023 09:55:36" level=warning msg="crowdsecurity/spring4shell_cve-2022-22965 : overwrite"
- time="25-08-2023 09:55:36" level=warning msg="crowdsecurity/vmware-cve-2022-22954 : overwrite"
- time="25-08-2023 09:55:36" level=warning msg="crowdsecurity/CVE-2022-37042 : overwrite"
- time="25-08-2023 09:55:36" level=warning msg="crowdsecurity/CVE-2022-41082 : overwrite"
- time="25-08-2023 09:55:36" level=warning msg="crowdsecurity/CVE-2022-35914 : overwrite"
- time="25-08-2023 09:55:36" level=warning msg="crowdsecurity/CVE-2022-40684 : overwrite"
- time="25-08-2023 09:55:36" level=warning msg="crowdsecurity/CVE-2022-26134 : overwrite"
- time="25-08-2023 09:55:36" level=warning msg="crowdsecurity/CVE-2022-42889 : overwrite"
- time="25-08-2023 09:55:36" level=warning msg="crowdsecurity/CVE-2022-41697 : overwrite"
- time="25-08-2023 09:55:36" level=warning msg="crowdsecurity/CVE-2022-46169 : overwrite"
- time="25-08-2023 09:55:36" level=warning msg="crowdsecurity/CVE-2022-44877 : overwrite"
- time="25-08-2023 09:55:36" level=warning msg="crowdsecurity/CVE-2019-18935 : overwrite"
- time="25-08-2023 09:55:36" level=warning msg="crowdsecurity/netgear_rce : overwrite"
- time="25-08-2023 09:55:36" level=warning msg="crowdsecurity/http-cve : overwrite"
- time="25-08-2023 09:55:36" level=warning msg="crowdsecurity/http-cve : overwrite"
- time="25-08-2023 09:55:36" level=warning msg="crowdsecurity/base-http-scenarios : overwrite"
- time="25-08-2023 09:55:36" level=warning msg="crowdsecurity/base-http-scenarios : overwrite"
- time="25-08-2023 09:55:36" level=warning msg="crowdsecurity/nginx : overwrite"
- time="25-08-2023 09:55:36" level=info msg="/etc/crowdsec/collections/http-cve.yaml already exists."
- time="25-08-2023 09:55:36" level=info msg="/etc/crowdsec/collections/base-http-scenarios.yaml already exists."
- time="25-08-2023 09:55:36" level=info msg="/etc/crowdsec/collections/nginx.yaml already exists."
- time="25-08-2023 09:55:36" level=info msg="Enabled crowdsecurity/nginx"
- time="25-08-2023 09:55:36" level=info msg="Run 'sudo systemctl reload crowdsec' for the new configuration to be effective."
- Running: cscli collections install "crowdsecurity/http-cve"
- time="25-08-2023 09:55:38" level=warning msg="crowdsecurity/http-cve-2021-41773 : overwrite"
- time="25-08-2023 09:55:38" level=warning msg="crowdsecurity/http-cve-2021-42013 : overwrite"
- time="25-08-2023 09:55:38" level=warning msg="crowdsecurity/grafana-cve-2021-43798 : overwrite"
- time="25-08-2023 09:55:38" level=warning msg="crowdsecurity/vmware-vcenter-vmsa-2021-0027 : overwrite"
- time="25-08-2023 09:55:38" level=warning msg="crowdsecurity/fortinet-cve-2018-13379 : overwrite"
- time="25-08-2023 09:55:38" level=warning msg="crowdsecurity/pulse-secure-sslvpn-cve-2019-11510 : overwrite"
- time="25-08-2023 09:55:38" level=warning msg="crowdsecurity/f5-big-ip-cve-2020-5902 : overwrite"
- time="25-08-2023 09:55:38" level=warning msg="crowdsecurity/thinkphp-cve-2018-20062 : overwrite"
- time="25-08-2023 09:55:38" level=warning msg="crowdsecurity/apache_log4j2_cve-2021-44228 : overwrite"
- time="25-08-2023 09:55:38" level=warning msg="crowdsecurity/jira_cve-2021-26086 : overwrite"
- time="25-08-2023 09:55:38" level=warning msg="crowdsecurity/spring4shell_cve-2022-22965 : overwrite"
- time="25-08-2023 09:55:38" level=warning msg="crowdsecurity/vmware-cve-2022-22954 : overwrite"
- time="25-08-2023 09:55:38" level=warning msg="crowdsecurity/CVE-2022-37042 : overwrite"
- time="25-08-2023 09:55:38" level=warning msg="crowdsecurity/CVE-2022-41082 : overwrite"
- time="25-08-2023 09:55:38" level=warning msg="crowdsecurity/CVE-2022-35914 : overwrite"
- time="25-08-2023 09:55:38" level=warning msg="crowdsecurity/CVE-2022-40684 : overwrite"
- time="25-08-2023 09:55:38" level=warning msg="crowdsecurity/CVE-2022-26134 : overwrite"
- time="25-08-2023 09:55:38" level=warning msg="crowdsecurity/CVE-2022-42889 : overwrite"
- time="25-08-2023 09:55:38" level=warning msg="crowdsecurity/CVE-2022-41697 : overwrite"
- time="25-08-2023 09:55:38" level=warning msg="crowdsecurity/CVE-2022-46169 : overwrite"
- time="25-08-2023 09:55:38" level=warning msg="crowdsecurity/CVE-2022-44877 : overwrite"
- time="25-08-2023 09:55:38" level=warning msg="crowdsecurity/CVE-2019-18935 : overwrite"
- time="25-08-2023 09:55:38" level=warning msg="crowdsecurity/netgear_rce : overwrite"
- time="25-08-2023 09:55:38" level=warning msg="crowdsecurity/http-cve : overwrite"
- time="25-08-2023 09:55:38" level=info msg="/etc/crowdsec/collections/http-cve.yaml already exists."
- time="25-08-2023 09:55:38" level=info msg="Enabled crowdsecurity/http-cve"
- time="25-08-2023 09:55:38" level=info msg="Run 'sudo systemctl reload crowdsec' for the new configuration to be effective."
- Running: cscli collections install "crowdsecurity/whitelist-good-actors"
- time="25-08-2023 09:55:40" level=warning msg="crowdsecurity/seo-bots-whitelist : overwrite"
- time="25-08-2023 09:55:40" level=warning msg="crowdsecurity/cdn-whitelist : overwrite"
- time="25-08-2023 09:55:40" level=warning msg="crowdsecurity/rdns : overwrite"
- time="25-08-2023 09:55:40" level=warning msg="crowdsecurity/whitelist-good-actors : overwrite"
- time="25-08-2023 09:55:40" level=info msg="/etc/crowdsec/collections/whitelist-good-actors.yaml already exists."
- time="25-08-2023 09:55:40" level=info msg="Enabled crowdsecurity/whitelist-good-actors"
- time="25-08-2023 09:55:40" level=info msg="Run 'sudo systemctl reload crowdsec' for the new configuration to be effective."
- time="25-08-2023 09:55:40" level=warning msg="can't load CAPI credentials from '/etc/crowdsec//online_api_credentials.yaml' (missing field)"
- time="25-08-2023 09:55:40" level=info msg="push and pull to Central API disabled"
- time="25-08-2023 09:55:40" level=warning msg="can't load CAPI credentials from '/etc/crowdsec//online_api_credentials.yaml' (missing field)"
- time="25-08-2023 09:55:40" level=info msg="push and pull to Central API disabled"
- time="25-08-2023 09:55:40" level=info msg="Enabled feature flags: <none>"
- time="25-08-2023 09:55:40" level=info msg="Crowdsec v1.5.2-4fbc3402fba932c8bd34b671527dcf7909d264c0"
- time="25-08-2023 09:55:40" level=info msg="Loading prometheus collectors"
- time="25-08-2023 09:55:40" level=warning msg="Communication with CrowdSec Central API disabled from configuration file"
- time="25-08-2023 09:55:40" level=info msg="push and pull to Central API disabled"
- time="25-08-2023 09:55:40" level=info msg="CrowdSec Local API listening on 0.0.0.0:8080"
- time="25-08-2023 09:55:40" level=info msg="Loading grok library /etc/crowdsec/patterns"
- time="25-08-2023 09:55:41" level=info msg="Loading enrich plugins"
- time="25-08-2023 09:55:41" level=info msg="Successfully registered enricher 'GeoIpCity'"
- time="25-08-2023 09:55:41" level=info msg="Successfully registered enricher 'GeoIpASN'"
- time="25-08-2023 09:55:41" level=info msg="Successfully registered enricher 'IpToRange'"
- time="25-08-2023 09:55:41" level=info msg="Successfully registered enricher 'reverse_dns'"
- time="25-08-2023 09:55:41" level=info msg="Successfully registered enricher 'ParseDate'"
- time="25-08-2023 09:55:41" level=info msg="Successfully registered enricher 'UnmarshalJSON'"
- time="25-08-2023 09:55:41" level=info msg="Loading parsers from 9 files"
- time="25-08-2023 09:55:41" level=info msg="Loaded 1 parser nodes" file=/etc/crowdsec/parsers/s00-raw/cri-logs.yaml stage=s00-raw
- time="25-08-2023 09:55:41" level=info msg="Loaded 1 parser nodes" file=/etc/crowdsec/parsers/s00-raw/docker-logs.yaml stage=s00-raw
- time="25-08-2023 09:55:41" level=info msg="Loaded 2 parser nodes" file=/etc/crowdsec/parsers/s00-raw/syslog-logs.yaml stage=s00-raw
- time="25-08-2023 09:55:41" level=info msg="Loaded 1 parser nodes" file=/etc/crowdsec/parsers/s01-parse/nginx-logs.yaml stage=s01-parse
- time="25-08-2023 09:55:41" level=info msg="Loaded 1 parser nodes" file=/etc/crowdsec/parsers/s01-parse/sshd-logs.yaml stage=s01-parse
- time="25-08-2023 09:55:41" level=info msg="Loaded 1 parser nodes" file=/etc/crowdsec/parsers/s02-enrich/dateparse-enrich.yaml stage=s02-enrich
- time="25-08-2023 09:55:41" level=info msg="Loaded 1 parser nodes" file=/etc/crowdsec/parsers/s02-enrich/geoip-enrich.yaml stage=s02-enrich
- time="25-08-2023 09:55:41" level=info msg="Loaded 1 parser nodes" file=/etc/crowdsec/parsers/s02-enrich/http-logs.yaml stage=s02-enrich
- time="25-08-2023 09:55:41" level=info msg="Loaded 1 parser nodes" file=/etc/crowdsec/parsers/s02-enrich/whitelists.yaml stage=s02-enrich
- time="25-08-2023 09:55:41" level=info msg="Loaded 10 nodes from 3 stages"
- time="25-08-2023 09:55:41" level=info msg="Loading postoverflow parsers"
- time="25-08-2023 09:55:41" level=info msg="Loaded 1 parser nodes" file=/etc/crowdsec/postoverflows/s00-enrich/rdns.yaml stage=s00-enrich
- time="25-08-2023 09:55:41" level=info msg="Loaded 1 parser nodes" file=/etc/crowdsec/postoverflows/s01-whitelist/cdn-whitelist.yaml stage=s01-whitelist
- time="25-08-2023 09:55:41" level=info msg="Loaded 1 parser nodes" file=/etc/crowdsec/postoverflows/s01-whitelist/seo-bots-whitelist.yaml stage=s01-whitelist
- time="25-08-2023 09:55:41" level=info msg="Loaded 3 nodes from 2 stages"
- time="25-08-2023 09:55:41" level=info msg="Loading 37 scenario files"
- time="25-08-2023 09:55:41" level=info msg="Adding leaky bucket" cfg=dawn-feather file=/etc/crowdsec/scenarios/http-xss-probing.yaml name=crowdsecurity/http-xss-probbing
- time="25-08-2023 09:55:41" level=info msg="Adding leaky bucket" cfg=young-dawn file=/etc/crowdsec/scenarios/http-sqli-probing.yaml name=crowdsecurity/http-sqli-probbing-detection
- time="25-08-2023 09:55:41" level=info msg="Adding trigger bucket" cfg=falling-hill file=/etc/crowdsec/scenarios/vmware-vcenter-vmsa-2021-0027.yaml name=crowdsecurity/vmware-vcenter-vmsa-2021-0027
- time="25-08-2023 09:55:41" level=info msg="Adding trigger bucket" cfg=lively-dawn file=/etc/crowdsec/scenarios/http-open-proxy.yaml name=crowdsecurity/http-open-proxy
- time="25-08-2023 09:55:41" level=info msg="Adding trigger bucket" cfg=lively-glitter file=/etc/crowdsec/scenarios/spring4shell_cve-2022-22965.yaml name=crowdsecurity/spring4shell_cve-2022-22965
- time="25-08-2023 09:55:41" level=info msg="Adding trigger bucket" cfg=muddy-smoke file=/etc/crowdsec/scenarios/CVE-2022-26134.yaml name=crowdsecurity/CVE-2022-26134
- time="25-08-2023 09:55:41" level=info msg="Adding leaky bucket" cfg=quiet-waterfall file=/etc/crowdsec/scenarios/ssh-bf.yaml name=crowdsecurity/ssh-bf
- time="25-08-2023 09:55:41" level=info msg="Adding leaky bucket" cfg=icy-water file=/etc/crowdsec/scenarios/ssh-bf.yaml name=crowdsecurity/ssh-bf_user-enum
- time="25-08-2023 09:55:41" level=info msg="Adding trigger bucket" cfg=dry-forest file=/etc/crowdsec/scenarios/netgear_rce.yaml name=crowdsecurity/netgear_rce
- time="25-08-2023 09:55:41" level=info msg="Adding trigger bucket" cfg=withered-rain file=/etc/crowdsec/scenarios/CVE-2019-18935.yaml name=crowdsecurity/CVE-2019-18935
- time="25-08-2023 09:55:41" level=info msg="Adding trigger bucket" cfg=holy-shape file=/etc/crowdsec/scenarios/fortinet-cve-2018-13379.yaml name=crowdsecurity/fortinet-cve-2018-13379
- time="25-08-2023 09:55:41" level=info msg="Adding leaky bucket" cfg=cool-sun file=/etc/crowdsec/scenarios/http-sensitive-files.yaml name=crowdsecurity/http-sensitive-files
- time="25-08-2023 09:55:41" level=info msg="Adding leaky bucket" cfg=falling-leaf file=/etc/crowdsec/scenarios/ssh-slow-bf.yaml name=crowdsecurity/ssh-slow-bf
- time="25-08-2023 09:55:41" level=info msg="Adding leaky bucket" cfg=green-butterfly file=/etc/crowdsec/scenarios/ssh-slow-bf.yaml name=crowdsecurity/ssh-slow-bf_user-enum
- time="25-08-2023 09:55:41" level=info msg="Adding trigger bucket" cfg=muddy-frost file=/etc/crowdsec/scenarios/f5-big-ip-cve-2020-5902.yaml name=crowdsecurity/f5-big-ip-cve-2020-5902
- time="25-08-2023 09:55:41" level=info msg="Adding leaky bucket" cfg=white-butterfly file=/etc/crowdsec/scenarios/http-backdoors-attempts.yaml name=crowdsecurity/http-backdoors-attempts
- time="25-08-2023 09:55:41" level=info msg="Adding leaky bucket" cfg=winter-haze file=/etc/crowdsec/scenarios/CVE-2022-46169.yaml name=crowdsecurity/CVE-2022-46169-bf
- time="25-08-2023 09:55:41" level=info msg="Adding trigger bucket" cfg=dry-frog file=/etc/crowdsec/scenarios/CVE-2022-46169.yaml name=crowdsecurity/CVE-2022-46169-cmd
- time="25-08-2023 09:55:41" level=info msg="Adding trigger bucket" cfg=little-breeze file=/etc/crowdsec/scenarios/http-cve-2021-42013.yaml name=crowdsecurity/http-cve-2021-42013
- time="25-08-2023 09:55:41" level=info msg="Adding trigger bucket" cfg=dry-wind file=/etc/crowdsec/scenarios/http-w00tw00t.yaml name=ltsich/http-w00tw00t
- time="25-08-2023 09:55:41" level=info msg="Adding trigger bucket" cfg=nameless-pine file=/etc/crowdsec/scenarios/CVE-2022-44877.yaml name=crowdsecurity/CVE-2022-44877
- time="25-08-2023 09:55:41" level=info msg="Adding leaky bucket" cfg=solitary-smoke file=/etc/crowdsec/scenarios/CVE-2022-41697.yaml name=crowdsecurity/CVE-2022-41697
- time="25-08-2023 09:55:41" level=info msg="Adding trigger bucket" cfg=broken-brook file=/etc/crowdsec/scenarios/vmware-cve-2022-22954.yaml name=crowdsecurity/vmware-cve-2022-22954
- time="25-08-2023 09:55:41" level=info msg="Adding trigger bucket" cfg=fragrant-resonance file=/etc/crowdsec/scenarios/jira_cve-2021-26086.yaml name=crowdsecurity/jira_cve-2021-26086
- time="25-08-2023 09:55:41" level=info msg="Adding leaky bucket" cfg=nameless-water file=/etc/crowdsec/scenarios/http-generic-bf.yaml name=crowdsecurity/http-generic-bf
- time="25-08-2023 09:55:41" level=info msg="Adding leaky bucket" cfg=misty-bush file=/etc/crowdsec/scenarios/http-generic-bf.yaml name=LePresidente/http-generic-401-bf
- time="25-08-2023 09:55:41" level=info msg="Adding leaky bucket" cfg=cold-firefly file=/etc/crowdsec/scenarios/http-generic-bf.yaml name=LePresidente/http-generic-403-bf
- time="25-08-2023 09:55:41" level=info msg="Adding leaky bucket" cfg=rough-moon file=/etc/crowdsec/scenarios/nginx-req-limit-exceeded.yaml name=crowdsecurity/nginx-req-limit-exceeded
- time="25-08-2023 09:55:41" level=info msg="Adding trigger bucket" cfg=dark-shadow file=/etc/crowdsec/scenarios/apache_log4j2_cve-2021-44228.yaml name=crowdsecurity/apache_log4j2_cve-2021-44228
- time="25-08-2023 09:55:41" level=info msg="Adding leaky bucket" cfg=solitary-flower file=/etc/crowdsec/scenarios/http-path-traversal-probing.yaml name=crowdsecurity/http-path-traversal-probing
- time="25-08-2023 09:55:41" level=info msg="Adding leaky bucket" cfg=snowy-thunder file=/etc/crowdsec/scenarios/http-crawl-non_statics.yaml name=crowdsecurity/http-crawl-non_statics
- time="25-08-2023 09:55:41" level=info msg="Adding trigger bucket" cfg=throbbing-brook file=/etc/crowdsec/scenarios/CVE-2022-40684.yaml name=crowdsecurity/fortinet-cve-2022-40684
- time="25-08-2023 09:55:41" level=info msg="Adding trigger bucket" cfg=damp-sun file=/etc/crowdsec/scenarios/CVE-2022-42889.yaml name=crowdsecurity/CVE-2022-42889
- time="25-08-2023 09:55:41" level=info msg="Adding trigger bucket" cfg=proud-cloud file=/etc/crowdsec/scenarios/thinkphp-cve-2018-20062.yaml name=crowdsecurity/thinkphp-cve-2018-20062
- time="25-08-2023 09:55:41" level=info msg="Adding trigger bucket" cfg=small-frog file=/etc/crowdsec/scenarios/pulse-secure-sslvpn-cve-2019-11510.yaml name=crowdsecurity/pulse-secure-sslvpn-cve-2019-11510
- time="25-08-2023 09:55:41" level=info msg="Adding trigger bucket" cfg=dark-fog file=/etc/crowdsec/scenarios/CVE-2022-35914.yaml name=crowdsecurity/CVE-2022-35914
- time="25-08-2023 09:55:41" level=info msg="Adding leaky bucket" cfg=dawn-sunset file=/etc/crowdsec/scenarios/http-bad-user-agent.yaml name=crowdsecurity/http-bad-user-agent
- time="25-08-2023 09:55:41" level=info msg="Adding trigger bucket" cfg=polished-sun file=/etc/crowdsec/scenarios/CVE-2022-41082.yaml name=crowdsecurity/CVE-2022-41082
- time="25-08-2023 09:55:41" level=info msg="Adding trigger bucket" cfg=young-forest file=/etc/crowdsec/scenarios/grafana-cve-2021-43798.yaml name=crowdsecurity/grafana-cve-2021-43798
- time="25-08-2023 09:55:41" level=info msg="Adding leaky bucket" cfg=black-pine file=/etc/crowdsec/scenarios/http-probing.yaml name=crowdsecurity/http-probing
- time="25-08-2023 09:55:41" level=info msg="Adding trigger bucket" cfg=frosty-breeze file=/etc/crowdsec/scenarios/http-cve-2021-41773.yaml name=crowdsecurity/http-cve-2021-41773
- time="25-08-2023 09:55:41" level=info msg="Adding trigger bucket" cfg=frosty-dawn file=/etc/crowdsec/scenarios/CVE-2022-37042.yaml name=crowdsecurity/CVE-2022-37042
- time="25-08-2023 09:55:41" level=warning msg="Loaded 42 scenarios"
- time="25-08-2023 09:55:41" level=info msg="loading acquisition file : /etc/crowdsec/acquis.yaml"
- time="25-08-2023 09:55:41" level=warning msg="No matching files for pattern /var/log/nginx/*.log" type=file
- time="25-08-2023 09:55:41" level=warning msg="No matching files for pattern ./tests/nginx/nginx.log" type=file
- time="25-08-2023 09:55:41" level=warning msg="No matching files for pattern /var/log/auth.log" type=file
- time="25-08-2023 09:55:41" level=info msg="Adding file /var/log/syslog to datasources" type=file
- time="25-08-2023 09:55:41" level=warning msg="No matching files for pattern /var/log/apache2/*.log" type=file
- time="25-08-2023 09:55:41" level=info msg="Starting processing data"
- time="25-08-2023 09:55:41" level=warning msg="/var/log/syslog is a directory, ignoring it." type=file
- time="25-08-2023 09:55:41" level=info msg="127.0.0.1 - [Fri, 25 Aug 2023 09:55:41 UTC] \"POST /v1/watchers/login HTTP/1.1 200 126.000488ms \"crowdsec/v1.5.2-4fbc3402fba932c8bd34b671527dcf7909d264c0\" \""
- time="25-08-2023 09:56:41" level=info msg="127.0.0.1 - [Fri, 25 Aug 2023 09:56:41 UTC] \"GET /v1/heartbeat HTTP/1.1 200 32.28204ms \"crowdsec/v1.5.2-4fbc3402fba932c8bd34b671527dcf7909d264c0\" \""
Advertisement
Add Comment
Please, Sign In to add comment