Send logs from Graylog to crowdsec

If you do not know crowdsec : it’s a kind of more modern fail2ban system. It can parse logs, detect brutforce or other hostil users, and can trigger alerts (which can then be consummed by bouncers to either alert you, ban an IP etc.)

As crowdsec must access various logs, and all those logs were already sent to Graylog, I’ve setup Graylog to forward all my logs to a single crowdsec instance. If you’re interested, here it is : tuto:monitoring:graylog_to_crowdsec [WikiT]

Cheers,
Daniel

1 Like

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.