Skip to main content

Console Health Check Issues

The CrowdSec Console monitors the health of your CrowdSec stack (Security Engines, Log Processors, remediation components and blocklist integrations) and raises alerts when issues are detected.
This page lists all possible health check issues, their trigger conditions, and links to detailed troubleshooting guides.

Understanding Issue Criticality

  • 🔥 Critical: Immediate attention required - core functionality is impaired
  • ⚠️ High: Important issue that should be addressed soon - may impact protection effectiveness
  • 💡 Recomended: Additionnal actions that will continue improving your security posture (comming in next iterations of Stack Health)
  • 🌟 Bonus : Optimization advises and upper tier recommendation with great return on value (comming in next iterations of Stack Health)

Health Check Issues Overview

IssueCriticalitySummaryResolution
Security Engine Offline🔥 CriticalSecurity Engine has not reported to Console for 24+ hoursTroubleshooting
Engine No Alerts⚠️ HighNo alerts generated in the last 48 hoursTroubleshooting
Engine Too Many Alerts⚠️ HighMore than 250,000 alerts in 6 hoursTroubleshooting
Log Processor Offline🔥 CriticalLog Processor has not checked in with LAPI for 24+ hoursTroubleshooting
LP No Alerts⚠️ HighLog Processor has not generated alerts in 48 hoursTroubleshooting
LP No Logs Read🔥 CriticalNo logs acquired in the last 24 hoursTroubleshooting
LP No Logs Parsed🔥 CriticalLogs read but none parsed in the last 48 hoursTroubleshooting
Firewall Integration Offline🔥 CriticalFirewall has not pulled from BLaaS endpoint for 24+ hoursTroubleshooting
RC Integration Offline🔥 CriticalRemediation Component has not pulled from endpoint for 24+ hoursTroubleshooting

Issue Dependencies

Some issues are related and share common root causes:

  • Engine No Alerts may be caused by:

    • LP No Logs Read
    • LP No Logs Parsed
    • Scenarios not installed or in simulation mode
  • LP No Alerts may be caused by:

    • LP No Logs Read
    • LP No Logs Parsed
    • Scenarios not matching the parsed events

Understanding these dependencies helps you troubleshoot more efficiently by addressing root causes first.

Future Enhancements

For planned and experimental health checks, see Future Console Health Check Issues page for planned features including:

  • Enhanced configuration validation
  • Blocklists optimization recommendations
  • Collection update notifications
  • False positive prevention checks
  • Premium feature recommendation based on detected benefit

Getting Help

If you've followed the troubleshooting guides and still need assistance: