IP signalledΒΆ
Plugin ID: crowdsec:signalled
Provided tokens
| Token | Description |
|---|---|
[user] |
The current user. Alias: current_user |
[event] |
The event. |
[event:crowdsec_ip] |
The ip address. |
[event:crowdsec_scenario] |
The CrowdSec scenario. |
[event] |
The event. |
[event:machine_name] |
The machine name of the ECA event. |
[session_user] |
The user account that dispatched the event, regardless if ECA is processing models under a different account. This is only available if ECA is configured to always run under a specific account. |
Fires when an IP address is signalled upstream to the CrowdSec API.
The [event:crowdsec_ip] token contains the signalled IP address and [event:crowdsec_scenario] identifies the triggered scenario.