crowdsec/config/profiles.yaml

26 lines
798 B
YAML
Raw Normal View History

2020-05-15 09:39:16 +00:00
profile: default_remediation
filter: "sig.Labels.remediation == 'true' && not sig.Whitelisted"
2020-05-15 09:39:16 +00:00
api: true # If no api: specified, will use the default config in default.yaml
remediation:
ban: true
slow: true
captcha: true
duration: 4h
outputs:
- plugin: database
2020-05-15 09:39:16 +00:00
---
profile: default_notification
filter: "sig.Labels.remediation != 'true'"
#remediation is empty, it means non taken
api: false
outputs:
- plugin: database # If we do not want to push, we can remove this line and the next one
2020-05-15 09:39:16 +00:00
store: false
---
profile: send_false_positif_to_API
filter: "sig.Whitelisted == true && sig.Labels.remediation == 'true'"
#remediation is empty, it means non taken
api: true
outputs:
- plugin: database # If we do not want to push, we can remove this line and the next one
store: false