CrowdSec — collective defense

CrowdSec
Active
Scenarios: 50
Active bans
2,026
Active bans
Alerts
203
Total
Bouncers
2
Active
Recent alerts 203
IP Scenario Time
198.51.100.14 crowdsecurity/ssh-bf 2026-10-11 19:22
198.51.100.32 crowdsecurity/http-probing 2026-10-11 18:26
198.51.100.14 crowdsecurity/http-crawl-non_statics 2026-10-11 19:08
198.51.100.11 crowdsecurity/http-probing 2026-10-11 19:03
198.51.100.11 crowdsecurity/http-probing 2026-10-11 16:00
198.51.100.29 crowdsecurity/http-bad-user-agent 2026-10-11 15:29
198.51.100.27 crowdsecurity/ssh-bf 2026-10-11 16:46
198.51.100.18 crowdsecurity/http-probing 2026-10-11 14:08
198.51.100.12 crowdsecurity/http-crawl-non_statics 2026-10-11 17:41
198.51.100.30 crowdsecurity/http-probing 2026-10-11 15:15
198.51.100.31 crowdsecurity/ssh-bf 2026-10-11 14:37
198.51.100.32 crowdsecurity/http-probing 2026-10-11 09:47
198.51.100.34 crowdsecurity/http-crawl-non_statics 2026-10-11 17:51
198.51.100.19 crowdsecurity/http-bad-user-agent 2026-10-11 16:17
198.51.100.31 crowdsecurity/http-probing 2026-10-11 12:12
198.51.100.21 crowdsecurity/http-bad-user-agent 2026-10-11 14:39
198.51.100.16 crowdsecurity/http-bad-user-agent 2026-10-11 08:56
198.51.100.29 crowdsecurity/nginx-req-limit-exceeded 2026-10-11 14:38
198.51.100.13 crowdsecurity/http-crawl-non_statics 2026-10-11 12:36
198.51.100.12 crowdsecurity/nginx-req-limit-exceeded 2026-10-11 10:18

CrowdSec decisions and alerts without cscli

CrowdSec reads your logs, matches them against scenarios, and decides that an address should be blocked. Something else has to carry that decision out — that is the bouncer, and the split trips up nearly everyone the first time. An address can appear in the decision list and still be reaching your server, because no bouncer is installed to enforce it.

This page shows both halves: the current decisions with the scenario that triggered them and the time remaining, and the bouncers registered to act on them. If the second list is empty, CrowdSec is an alerting system and nothing more.

It is a fair question whether to run CrowdSec alongside Fail2ban, and the answer is usually yes. They overlap but do not collide: Fail2ban reacts to what has already happened on your machine, while CrowdSec also draws on addresses reported by everyone else running it, so an attacker often arrives already known. The other difference worth noting is that the official CrowdSec console is a hosted service; this page is not, and reads only the local API.