IP blockedΒΆ
Plugin ID: crowdsec:blocked
Provided tokens
| Token | Description |
|---|---|
[user] |
The current user. Alias: current_user |
[event] |
The event. |
[event:crowdsec_ip] |
The ip address. |
[event] |
The event. |
[event:machine_name] |
The machine name of the ECA event. |
[session_user] |
The user account that dispatched the event, regardless if ECA is processing models under a different account. This is only available if ECA is configured to always run under a specific account. |
Fires when a request from an IP address is blocked by CrowdSec.
The [event:crowdsec_ip] token contains the blocked IP address.