How to retrieve the User-Agent in a Postoverflow scenario?
Hello, Iβm trying to set up a Postoverflow whitelist to whitelist an IP if it triggers an alert on a specific UA, but it doesnβt seem to be working. Do you have any idea why?
line: 192.192.192.192 - - [17/Oct/2025:09:52:41 +0200] "GET /robots.txt HTTP/1.1" 200 1020 "-" "Screaming Frog SEO Spider/22.2"
β s00-raw
| β π΄ crowdsecurity/syslog-logs
| β π’ crowdsecurity/non-syslog (+5 ~8)
β s01-parse
| β π’ crowdsecurity/apache2-logs (+21 ~2)
β s02-enrich
| β π’ crowdsecurity/dateparse-enrich (+2 ~2)
| β π΄ crowdsecurity/enrich-user-agent-year
| β π’ crowdsecurity/geoip-enrich (+13)
| β π’ crowdsecurity/http-logs (+7)
| β π’ mywhitelists (unchanged)
| β π’ crowdsecurity/nextcloud-whitelist (unchanged)
| β π’ crowdsecurity/public-dns-allowlist (unchanged)
| β π’ crowdsecurity/whitelists (unchanged)
β-------- parser success π’
β Scenarios
β π’ crowdsecurity/http-bad-user-agent
β π’ crowdsecurity/http-crawl-non_statics
8 Replies
Important Information
This post has been marked as resolved. If this is a mistake please press the red button below or type
/unresolveΒ© Created By WhyAydan for CrowdSec β€οΈ
I had tried that as well.
@bbuddha
should be using the
# replace no?
I'll try. By the way, with cscli explain can we see if a whitelist postoverflow is triggered?
not currently, postoverflows are not supported via
cscli explain
there is an edge case, where if you provide enough logs to trigger a scenario then it will show for one explain within the bulk but its kinda badhahahahaha yes ok

thx
Resolving How to retrieve the User-Agent in a Postoverflow scenario?
This has now been resolved. If you think this is a mistake please run
/unresolve