Sign inSign up

giiibates/crowdsec-toolbox

By giiibates

โ€ขUpdated 13 days ago

Image
Security
Data science
Monitoring & observability
0

597

giiibates/crowdsec-toolbox repository overview

CrowdSec Toolbox

โ Turn CrowdSec decisions into action and insight

MIT License Python 3.13 or newer Two standalone tools Docker Compose deployment

Abuse reportingโ  ยท Metrics exportโ  ยท Dashboardsโ  ยท Licenseโ 

CrowdSec can identify and block hostile traffic. CrowdSec Toolbox helps you use those decisions after they are made: send an abuse report to the responsible network contact, or export decision data to the time-series backend you already monitor. Each tool is independent, so you can run only the part you need.

โ Features at a glance

crowdsec-abuse-reporterโ crowdsec-metrics-exporterโ 
What it doesTurns CrowdSec bans into abuse reportsExports CrowdSec decisions as time series
๐Ÿ“ฅ SourceCrowdSec Local API (LAPI), directCrowdSec Local API (LAPI), direct
๐Ÿ“ค OutputX-ARF v4 email to the responsible abuse contactInfluxDB 2.x or QuestDB (line protocol over HTTP)
๐ŸŒ EnrichmentGeoIP (GeoLite2 City + ASN)โ€”
๐Ÿ“‡ Contact lookupAbusix DNS abuse-contact databaseโ€”
๐Ÿ” IdempotencySQLite, at-most-once per (AlertId, IPAddress)Backend-side deduplication, no local state
๐Ÿณ Runs asDocker container (own image), or cron/host scriptDocker container, or cron/host script
๐Ÿ“ฆ Dependencieshttpx, dnspython, geoip2requests, urllib3, httpx

โ Grafana dashboards

Both tools ship ready-made dashboards in their grafana/ directory โ€” import the JSON, pick your data source, and you have a working view of what CrowdSec is blocking. No provisioning, no plugins beyond the data source itself.

DashboardPanelsHighlights
Metrics exportdashboard_questdb.jsonโ 18World map of source IPs coloured per host, alert and event history, top countries, networks/ASN, scenarios, source IPs, and โ€” with the per-event export enabled โ€” top endpoints and target FQDNs
Abuse reportingdashboard_questdb.jsonโ 8A four-card KPI header (sent, failed, success rate, total), daily reports, top recipients, origin countries, and a paginated detail table

Country values render as flag emoji, and hosts keep a stable colour across panels. The shared host and scenario filters apply throughout; the country filter applies to every panel except the two event panels, whose table holds no geo columns.

โ Screenshots

Metrics export dashboard

Note

Both dashboards are developed and tested against **Grafana 13** using the v2 dashboard schema (`dashboard.grafana.app/v2`). Grafana validates that schema on import, so an older release will reject them. The metrics dashboard targets the [QuestDB data source plugin](https://grafana.com/grafana/plugins/questdb-questdb-datasource/); the InfluxDB variants are placeholders.

โ Deployment

Both tools provide Docker and Compose deployments. The metrics exporter can also run directly as a Python script on the CrowdSec host. They have separate entry points and their own pyproject.toml dependency manifests, so their deployments can be managed independently. Follow each tool's README for setup, configuration, and operating notes.

Important

*CrowdSec Toolbox* is an independent community project. It is not affiliated with, endorsed by, or sponsored by CrowdSec.

โ License

This repository is released under the MIT Licenseโ .


Buy Me a Beer โ 

Tag summary

Content type

Image

Digest

sha256:4c41593c1โ€ฆ

Size

44.8 MB

Last updated

13 days ago

docker pull giiibates/crowdsec-toolbox:metrics-exporter-latest