Skip to main content

Notification rule

CrowdSec Premium Feature

Notification rules allow you to customize the alerts and notifications you receive from your CrowdSec Console. By setting up specific rules, you can ensure that you are only notified about events that are relevant to your organization. This guide will walk you through the process of creating a notification rule for your linked integration.

You need at least one integration linked to your CrowdSec Console to create a notification rule. If you haven't linked an integration yet, please refer to the Integrations Overview for more information on how to do so.

Create a notification ruleโ€‹

  1. In the CrowdSec Console, navigate to Notification Rules and click on Add Rule.
CrowdSec Notification RuleCrowdSec Notification Rule
  1. Select the events you want to be notified about. You can only select one of the three categories at a time (Threat Hunting, Stack or Admin). Each of these categories contains a list of events that you can choose from. (The Threat Hunting category lets you select only one event, because its conditions differ from one event to another.)
CrowdSec Notification Rule Events SelectionCrowdSec Notification Rule Events Selection
  1. (Optional) Select conditions. Stack category allows you to filter on Security Engine(s). Threat Hunting > Alert trigger event allows you to select specific scenarios.

Engine condition:

CrowdSec Notification Rule Engine Condition SelectionCrowdSec Notification Rule Engine Condition Selection

Installed scenarios:

CrowdSec Notification Rule Scenario Condition SelectionCrowdSec Notification Rule Scenario Condition Selection
  1. Select destination, which is the integration you want to use for this rule. You can select multiple destinations for one rule. Destination input varies depending on the integration you selected. For example, the Slack integration lets you select a channel, while the Webhook integration lets you select a URL.
CrowdSec Notification Rule Destination SelectionCrowdSec Notification Rule Destination Selection
  1. Name and describe your rule.
CrowdSec Notification Rule InformationCrowdSec Notification Rule Information
  1. Click on Create to save your rule.

  2. Your rule will now appear in the list of notification rules for your integration. You can edit or delete it at any time.

CrowdSec Notification RuleCrowdSec Notification Rule
CrowdSec Docs
We use cookies

This site uses cookies to help us improve your experience. You can accept or decline below.