Signal scenario listΒΆ
Plugin ID: crowdsec:signalscenariolist
Provided tokens
| Token | Description |
|---|---|
[user] |
The current user. Alias: current_user |
[event] |
The event. |
[event:crowdsec_scenario_list] |
The CrowdSec object. |
[event] |
The event. |
[event:machine_name] |
The machine name of the ECA event. |
[session_user] |
The user account that dispatched the event, regardless if ECA is processing models under a different account. This is only available if ECA is configured to always run under a specific account. |
Fires when CrowdSec builds the list of scenarios for upstream signaling. Use this to control which scenarios are reported to the CrowdSec API.
The [event:crowdsec_scenario_list] token provides the current array of scenarios.