Difficulty Whitelisting AppSec CRS False Positives in Traefik Bouncer
problem timeout nginx + plguin lua
live_query(): ... timeout
Troubleshooting done:
- Network is OK: curl from Nginx pod to LAPI's /health endpoint works fine....Blocklist unsubscribe not working
cscli metrics and then running cscli decisions delete --scenario "firehol_cybercrime". The list disappeared from the metrics, so I waited for the next pull. After the next pull, I saw this in the logs:
```
time=2025-08-27T12:13:05+02:00 level=info msg=Starting community-blocklist update...
Scenario not working
Crowdsec Blocking Large File Upload - Immich
freebsd firewall bounce metrics missing
Is it possible to set remediation to false for specific ip adresses?
Selfhosted cloudflare tunnel + crowdSec?
Syslog not getting parsed...
cat the syslog file and see it being updated.
acquis:...firewall bouncer stops grabbing new decisions after a while
AlmaLinux 10: Update or Install fails
error: Verifying a signature using certificate 9082D8CACBBEB0DAB218BAB04C3D386C3CDF0DB4 (Crowdsec Rpm Archive <support@crowdsec.net>): 1. Certificiate 4C3D386C3CDF0DB4 invalid: certificate is not alive...
Installed on OPNsense and blocking unraid community store
ban disappeared before expiration
ngx.timer error when loading decisions
How to do without a service key and HTTP value?
scenarios_not_containing: ["http"] so that only the PHP bouncer can handle HTTP blocking. However, this does not work when a ModSecurity scenario is triggered.
After investigating, I found the reason: when I inspect the scenario in detail, I notice that the service key with the value http is missing (or something else, Iβm not sure if it should be there). Consequently, I cannot make it so that this is handled by the PHP bouncer....Error while parsing logs - schiz0phr3ne/sonarr-logs
Can't connect to remote LAPI with agent
config.yaml for my log processor (this is not running the LAPI server)
```yaml
common:...Updating Decisions List
cscli decision list
cscli decision list
cscli decisions list --origin CAPI
cscli decisions list --origin CAPI
Traefik logs only showing internal docker IP address.