Skip to content

Scenario listΒΆ

Plugin ID: crowdsec:scenariolist

Provided tokens

Token Description
[user] The current user.
Alias: current_user
[event] The event.
[event:crowdsec_scenario_list] The CrowdSec object.
[event] The event.
[event:machine_name] The machine name of the ECA event.
[session_user] The user account that dispatched the event, regardless if ECA is processing models under a different account. This is only available if ECA is configured to always run under a specific account.

Fires when CrowdSec builds the list of scenarios to monitor. Use this to dynamically add or modify scenarios in the list.

The [event:crowdsec_scenario_list] token provides the current array of scenarios.