Skip to main content

Console Health Check Issues

The CrowdSec Console monitors the health of your CrowdSec stack (Security Engines, Log Processors, remediation components and blocklist integrations) and raises alerts when issues are detected.
This page lists all possible health check issues, their trigger conditions, and links to detailed troubleshooting guides.

Understanding Issue Criticality

  • 🔥 Critical: Immediate attention required - core functionality is impaired
  • ⚠️ High: Important issue that should be addressed soon - may impact protection effectiveness
  • 💡 Recommended: Additionnal actions that will continue improving your security posture (comming in next iterations of Stack Health)
  • 🌟 Bonus : Optimization advises and upper tier recommendation with great return on value (comming in next iterations of Stack Health)

Health Check Issues Overview

IssueCriticalitySummaryResolution
Integration for Firewall Offline🔥 CriticalFirewall has not pulled from BLaaS endpoint for 24+ hoursTroubleshooting
Integration for RC Offline🔥 CriticalRemediation Component has not pulled from endpoint for 24+ hoursTroubleshooting
Log Processor No Alerts⚠️ HighLog Processor has not generated alerts in 48 hoursTroubleshooting
Log Processor No Logs Parsed🔥 CriticalLogs read but none parsed in the last 48 hoursTroubleshooting
Log Processor No Logs Read🔥 CriticalNo logs acquired in the last 24 hoursTroubleshooting
Log Processor Offline🔥 CriticalLog Processor has not checked in with LAPI for 24+ hoursTroubleshooting
Security Engine No Alerts⚠️ HighNo alerts generated in the last 48 hoursTroubleshooting
Security Engine Offline🔥 CriticalSecurity Engine has not reported to Console for 24+ hoursTroubleshooting
Security Engine Too Many Alerts⚠️ HighMore than 250,000 alerts in 6 hoursTroubleshooting

Issue Dependencies

Some issues are related and share common root causes:

  • Engine No Alerts may be caused by:

    • LP No Logs Read
    • LP No Logs Parsed
    • Scenarios not installed or in simulation mode
  • LP No Alerts may be caused by:

    • LP No Logs Read
    • LP No Logs Parsed
    • Scenarios not matching the parsed events

Understanding these dependencies helps you troubleshoot more efficiently by addressing root causes first.

Future Enhancements

For planned and experimental health checks, see Future Console Health Check Issues page for planned features including:

  • Enhanced configuration validation
  • Blocklists optimization recommendations
  • Collection update notifications
  • False positive prevention checks
  • Premium feature recommendation based on detected benefit

Getting Help

If you've followed the troubleshooting guides and still need assistance: