Skip to content

IP blockedΒΆ

Plugin ID: crowdsec:blocked

Provided tokens

Token Description
[user] The current user.
Alias: current_user
[event] The event.
[event:crowdsec_ip] The ip address.
[event] The event.
[event:machine_name] The machine name of the ECA event.
[session_user] The user account that dispatched the event, regardless if ECA is processing models under a different account. This is only available if ECA is configured to always run under a specific account.

Fires when a request from an IP address is blocked by CrowdSec.

The [event:crowdsec_ip] token contains the blocked IP address.