Skip to main content

Alert Explorer Overview

Enrolled Security Engines report the attacks they detect and block to the Console.
The Alert Explorer helps you better understand and monitor the activity in your environment: Group by IP, Breakdown by the key dimensions, Filter by any attribute...

Some questions the Alert Explorer can answerโ€‹

"Is something new attacking my stack?"

The breakdown charts at the top of the page show your alert activity over time, by behavior, source IP or any other dimension.
A spike that was not there last week stands out immediately, and one click on the chart isolates it. Walk through a full example in Investigate an attack wave.

"This IP showed up in a report. Did it hit me?"

Paste an IP, a CIDR range or a CVE identifier straight into the filter search: the Explorer recognizes it and offers to show every matching alert. See Search and filter.

"I only care about one part of my infrastructure."

Filter down to the engines, targets or behaviors you monitor, then save that perspective as a view pinned to your menu. See Custom views.

"What does my WAF actually block?"

The dedicated WAF view breaks down inbound exploitation attempts caught at the application layer. See The WAF view.

The pivot pointsโ€‹

Every investigation in the Explorer pivots around the same three families of dimensions, and you will meet them everywhere - as sections of the filter drawer, and as breakdown charts:

  • Where it comes from - source IP or range, country, autonomous system, and the reputation the CrowdSec network assigns to each attacker.
  • What it does - the behavior, the attack scenario, the CVE being exploited, the MITRE technique.
  • What it targets - your Security Engines, by name or tag, and the targeted IPs.

Learn the three families once, and both filtering and building breakdowns become the same gesture: pick a family, pick a dimension, pivot.

The anatomy of the pageโ€‹

The Alert Explorer: breakdown charts on top, filters and views bar, and the alerts table grouped by attacking IPThe Alert Explorer: breakdown charts on top, filters and views bar, and the alerts table grouped by attacking IP

Three layers, top to bottom:

  • Breakdown charts โ€” your activity over the selected period, split by the dimensions you choose (behaviors, source IPs, countries, scenarios, target engines...). Add, remove or zoom into any of them.
  • Filters and views โ€” the period selector, the filter drawer, and your saved views. Every chart and the table below react to them instantly.
  • The alerts table โ€” grouped by attacking IP by default, so a noisy repeat offender takes one row instead of drowning the page. Expand a row to see the individual attack sessions, or switch grouping off to list raw alerts.

From any row you can open the alert detail, pivot to the IP's CTI profile, or ban the attacker across your engines from the context menu.

Where the data comes fromโ€‹

The Explorer shows the alerts your Security Engines pushed to the Console, within your organization's alert quota and retention. Periods where your organization exceeded its quota appear as greyed "Out of quota" bands in the charts - see Alert quotas.

CrowdSec Docs
We use cookies

This site uses cookies to help us improve your experience. You can accept or decline below.