Crowdsec

From SME Server
Jump to navigationJump to search







crowdsec
NeedImage.svg
crowdsec logo
MaintainerUnnilennium
Urlhttps://app.crowdsec.net
Source: smeserver-crowdsec
Category

Security

Tags crowdsecWAFlog parser


Version

smecontribs 11:
smeserver-crowdsec
The latest version of smeserver-crowdsec is available in the SME repository, click on the version number(s) for more information.


Description

Crowdsec turns crowd-powered intelligence into tactical intelligence with actionable blocklists to maximize your SOC efficiency and reduce your costs. In other words, it helps you defends your servers from major new attacks by sharing with the community.

For SME, we rely on crowdsec-blocklist-mirror, crowdsec and crowdsec-firewall-bouncer-iptables. crowdsec-custom-bouncer is planned to be used.

We have added rules for qpsmtpd. Some general whitelists configurable.

Installation

First install the external repo

dnf install smeserver-extrarepositories-crowdsec
expand-template /etc/yum.smerepos.d/sme-base.repo

Install

dnf install smeserver-crowdsec

Then you will need to get an ID to register your engine on https://app.crowdsec.net, and execute

cscli console enroll YOURID

Configuration

you can list the available configuration with the following command :

config show crowdsec

Some of the properties are not shown, but are defaulted in a template or a script. Here a more comprehensive list with default and expected values :

property default values
IgnoreIP ip/bitmask,ip/bitmask a comma separated list of IP or CIDR networks which will never be blocked by fail2ban. Example: 12.15.22.4,17.20.0.0/16. All your local networks and networks allowed to access the server-manager are already automatically whitelisted
FilterLocalNetworks disabled enabled/disabled can be enabled or disabled (default is disabled). If set to enabled, local networks won't be whitelisted, and fail2ban can also ban hosts from the internal networks. Note that networks allowed to access the server-manager are not affected (they will never be blocked)
FilterAnyLANIP disabled enabled/disabled add a list of common LAN ip to not filter them by default (ie if disabled). 127.0.0.0/8, 192.168.0.0/16, 10.0.0.0/8, 172.16.0.0/12 are not filtered whether or not they are in your networks e-smith db. This is an extra precaution for most user not to shot themselves, but if you know what you do you can enable this filtering (ie remove the default whitelist)
access private, public should remains empty for localhost only, anyway service is set to only listen on localhost
status enabled enabled,disabled

simply modify value

config setprop crowdsec FilterAnyLANIP enabled

you can then issue

signal-event smeserver-crowdsec-update

CLI usage

while you can have a lot of info online on your crowdsec app interface, you have some interesting commands

# cscli metrics show acquisition bouncers parsers whitelists
╭───────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────╮
│ Acquisition Metrics                                                                                                           │
├─────────────────────────────────────┬────────────┬──────────────┬────────────────┬────────────────────────┬───────────────────┤
│ Source                              │ Lines read │ Lines parsed │ Lines unparsed │ Lines poured to bucket │ Lines whitelisted │
├─────────────────────────────────────┼────────────┼──────────────┼────────────────┼────────────────────────┼───────────────────┤
│ file:/var/log/audit/audit.log       │ 4.86k      │ 1.43k        │ 3.44k          │ -                      │ -                 │
│ file:/var/log/dovecot/dovecot.log   │ 312              │ -                      │ -                 │
│ file:/var/log/maillog               │ 18         │ -            │ 18             │ -                      │ -                 │
│ file:/var/log/messages              │ 1.03k      │ -            │ 1.03k          │ -                      │ -                 │
│ file:/var/log/qpsmtpd/qpsmtpd.log   │ 3149305            │ -                      │ -                 │
│ file:/var/log/secure                │ 2          │ -            │ 2              │ -                      │ -                 │
│ file:/var/log/sqpsmtpd/sqpsmtpd.log │ 14616130            │ -                      │ -                 │
│ file:/var/log/uqpsmtpd/uqpsmtpd.log │ 11010100            │ -                      │ -                 │
╰─────────────────────────────────────┴────────────┴──────────────┴────────────────┴────────────────────────┴───────────────────╯
╭───────────────────────────────────────────────────────────────────────────────────╮
│ Bouncer Metrics (cs-firewall-bouncer-1782358017) since 2026-06-25 05:39:13 +0000  │
│ UTC                                                                               │
├────────────────────────────┬──────────────────┬─────────────────┬─────────────────┤
│ Origin                     │ active_decisions │     dropped     │    processed    │
│                            │        IPs       │ bytes │ packets │ bytes │ packets │
├────────────────────────────┼──────────────────┼───────┼─────────┼───────┼─────────┤
│ CAPI (community blocklist)19.82k │ 8.63k │     198 │     - │       - │
│ cscli (manual decisions)000 │     - │       - │
│ lists:firehol_botscout_7d  │            1.07k │     - │       - │     - │       - │
│ lists:firehol_greensnow    │            3.65k │     - │       - │     - │       - │
│ lists:tor-exit-nodes       │            1.44k │     00 │     - │       - │
├────────────────────────────┼──────────────────┼───────┼─────────┼───────┼─────────┤
│                      Total │           25.98k │ 8.63k │     1987.58M │  38.58k │
╰────────────────────────────┴──────────────────┴───────┴─────────┴───────┴─────────╯
╭───────────────────────────────────────────────────────────────────╮
│ Parser Metrics                                                    │
├───────────────────────────────────────┬───────┬────────┬──────────┤
│ Parsers                               │ Hits  │ Parsed │ Unparsed │
├───────────────────────────────────────┼───────┼────────┼──────────┤
│ child-child-crowdsecurity/auditd-logs │ 4.86k │ 1.43k  │ 3.44k    │
│ child-crowdsecurity/auditd-logs       │ 4.86k │ 1.43k  │ 3.44k    │
│ child-crowdsecurity/dovecot-logs      │ 918        │
│ child-crowdsecurity/qpsmtpd-logs      │ 3535     │ -        │
│ child-crowdsecurity/sshd-logs         │ 32    │ -      │ 32       │
│ child-crowdsecurity/sshd-success-logs │ 2     │ -      │ 2        │
│ child-crowdsecurity/syslog-logs       │ 1.05k │ 1.05k  │ -        │
│ crowdsecurity/auditd-logs             │ 4.86k │ 1.43k  │ 3.44k    │
│ crowdsecurity/dateparse-enrich        │ 1.46k │ 1.46k  │ -        │
│ crowdsecurity/dovecot-logs            │ 312        │
│ crowdsecurity/geoip-enrich            │ 11      │ -        │
│ crowdsecurity/non-syslog              │ 5.43k │ 5.43k  │ -        │
│ crowdsecurity/public-dns-allowlist    │ 1.46k │ 1.46k  │ -        │
│ crowdsecurity/qpsmtpd-logs            │ 3535     │ -        │
│ crowdsecurity/qpsmtpd-whitelist       │ 3535     │ -        │
│ crowdsecurity/sshd-logs               │ 2     │ -      │ 2        │
│ crowdsecurity/sshd-success-logs       │ 2     │ -      │ 2        │
│ crowdsecurity/syslog-logs             │ 1.05k │ 1.05k  │ -        │
│ crowdsecurity/whitelists              │ 1.43k │ 1.43k  │ -        │
╰───────────────────────────────────────┴───────┴────────┴──────────╯
╭─────────────────────────────────────────────────────────────────────────────────────────────────────────────────╮
│ Whitelist Metrics                                                                                               │
├────────────────────────────────────┬───────────────────────────────────────────────────────┬──────┬─────────────┤
│ Whitelist                          │ Reason                                                │ Hits │ Whitelisted │
├────────────────────────────────────┼───────────────────────────────────────────────────────┼──────┼─────────────┤
│ crowdsecurity/public-dns-allowlist │ public DNS server                                     │ 1461 │ -           │
│ crowdsecurity/qpsmtpd-whitelist    │ IP de confiance pour le serveur de messagerie qpsmtpd │ 35   │ -           │
│ crowdsecurity/whitelists           │ private ipv4/ipv6 ip/ranges                           │ 1426 │ -           │
╰────────────────────────────────────┴───────────────────────────────────────────────────────┴──────┴─────────────╯
# cscli collections list
────────────────────────────────────────────────────────────────────────────────────────────────────────────────
 COLLECTIONS                                                                                                    
────────────────────────────────────────────────────────────────────────────────────────────────────────────────
 Name                                 📦 Status   Version  Local Path                                           
────────────────────────────────────────────────────────────────────────────────────────────────────────────────
 crowdsecurity/apache2                ✔️  enabled  0.2      /etc/crowdsec/collections/apache2.yaml               
 crowdsecurity/auditd                 ✔️  enabled  0.7      /etc/crowdsec/collections/auditd.yaml                
 crowdsecurity/base-http-scenarios    ✔️  enabled  1.4      /etc/crowdsec/collections/base-http-scenarios.yaml   
 crowdsecurity/dovecot                ✔️  enabled  0.2      /etc/crowdsec/collections/dovecot.yaml               
 crowdsecurity/http-cve               ✔️  enabled  3.0      /etc/crowdsec/collections/http-cve.yaml              
 crowdsecurity/linux                  ✔️  enabled  0.4      /etc/crowdsec/collections/linux.yaml                 
 crowdsecurity/mariadb                ✔️  enabled  0.2      /etc/crowdsec/collections/mariadb.yaml               
 crowdsecurity/mysql                  ✔️  enabled  0.2      /etc/crowdsec/collections/mysql.yaml                 
 crowdsecurity/postfix                ✔️  enabled  0.5      /etc/crowdsec/collections/postfix.yaml               
 crowdsecurity/proftpd                ✔️  enabled  0.2      /etc/crowdsec/collections/proftpd.yaml               
 crowdsecurity/smb                    ✔️  enabled  0.2      /etc/crowdsec/collections/smb.yaml                   
 crowdsecurity/sshd                   ✔️  enabled  0.9      /etc/crowdsec/collections/sshd.yaml                  
 crowdsecurity/whitelist-good-actors  ✔️  enabled  0.4      /etc/crowdsec/collections/whitelist-good-actors.yaml 
────────────────────────────────────────────────────────────────────────────────────────────────────────────────
# cscli parsers list
────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────
 PARSERS                                                                                                                    
────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────
 Name                                📦 Status          Version  Local Path                                                 
────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────
 crowdsecurity/apache2-logs          ✔️  enabled         1.5      /etc/crowdsec/parsers/s01-parse/apache2-logs.yaml          
 crowdsecurity/auditd-logs           ✔️  enabled         0.9      /etc/crowdsec/parsers/s01-parse/auditd-logs.yaml           
 crowdsecurity/dateparse-enrich      ✔️  enabled         0.2      /etc/crowdsec/parsers/s02-enrich/dateparse-enrich.yaml     
 crowdsecurity/dovecot-logs          ✔️  enabled         0.9      /etc/crowdsec/parsers/s01-parse/dovecot-logs.yaml          
 crowdsecurity/geoip-enrich          ✔️  enabled         0.5      /etc/crowdsec/parsers/s02-enrich/geoip-enrich.yaml         
 crowdsecurity/http-logs             ✔️  enabled         1.3      /etc/crowdsec/parsers/s02-enrich/http-logs.yaml            
 crowdsecurity/mariadb-logs          ✔️  enabled         0.4      /etc/crowdsec/parsers/s01-parse/mariadb-logs.yaml          
 crowdsecurity/mysql-logs            ✔️  enabled         0.4      /etc/crowdsec/parsers/s01-parse/mysql-logs.yaml            
 crowdsecurity/postfix-logs          ✔️  enabled         0.9      /etc/crowdsec/parsers/s01-parse/postfix-logs.yaml          
 crowdsecurity/postscreen-logs       ✔️  enabled         0.3      /etc/crowdsec/parsers/s01-parse/postscreen-logs.yaml       
 crowdsecurity/proftpd-logs          ✔️  enabled         0.3      /etc/crowdsec/parsers/s01-parse/proftpd-logs.yaml          
 crowdsecurity/public-dns-allowlist  ✔️  enabled         0.1      /etc/crowdsec/parsers/s02-enrich/public-dns-allowlist.yaml 
 crowdsecurity/qpsmtpd-logs          🏠  enabled,local           /etc/crowdsec/parsers/s01-parse/qpsmtpd-parser.yaml        
 crowdsecurity/qpsmtpd-whitelist     🏠  enabled,local           /etc/crowdsec/parsers/s02-enrich/qpsmtpd-whitelist.yaml    
 crowdsecurity/smb-logs              ✔️  enabled         0.2      /etc/crowdsec/parsers/s01-parse/smb-logs.yaml              
 crowdsecurity/sshd-logs             ✔️  enabled         3.1      /etc/crowdsec/parsers/s01-parse/sshd-logs.yaml             
 crowdsecurity/sshd-success-logs     ✔️  enabled         0.1      /etc/crowdsec/parsers/s01-parse/sshd-success-logs.yaml     
 crowdsecurity/syslog-logs           ✔️  enabled         1.0      /etc/crowdsec/parsers/s00-raw/syslog-logs.yaml             
 crowdsecurity/whitelists            🏠  enabled,local           /etc/crowdsec/parsers/s02-enrich/whitelists.yaml           
────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────

Uninstall

dnf remove smeserver-crowdsec  crowdsec

Bugs

Please raise bugs under the SME-Contribs section in bugzilla

and select the smeserver-crowdsec component or use this link


Below is an overview of the current issues for this contrib:

IDProductVersionStatusSummary (4 tasks)
13627SME Contribs11.0CONFIRMEDNFR: denylog collection
13623SME Contribs11.0CONFIRMEDNFR enable CRS collection
13622SME Contribs11.0CONFIRMEDNFR integrate mod_crowdsec
13621SME Contribs11.0CONFIRMEDNFR detect contribs and patch accordingly

Changelog

Only released version in smecontrib are listed here.

smeserver-crowdsec-0.9-1.el8.sme Changelog: SME 11 (smecontribs)

2026/06/24 Jean-Philippe Pialasse 0.9-1.sme
- initial SME 11 build [SME: 13626]
- added our log path for dovecot
- added our qpsmtpd parser, scenarios and log path
- global templated whitelist
- enable roundcube crowdsecurity/vpatch-CVE-2025-49113
- ProFTP enabled

- TODO handle creation of appi key and registration of bouncers