← All guides

CrowdSec: Attack IP as security data instead of visitor statistics

Delimitation

Use CrowdSec data only for attack detection and defense; Keep general visitor statistics and permanent access logging separate.

CrowdSec deliberately works IP-based: decisions can block IP addresses for defined periods of time. CrowdSec describes a maximum storage of complete attack IP for three months with subsequent gradual coarsening for attack data. This is security processing and should not be mixed with normal access logging.

Check after the change

Check browser memory and network requests and also view web server, proxy, application and provider logs separately. A single product setting does not automatically cover the entire processing chain.

Classification

To differentiate between technically necessary processing, security logging and permanent storage, additionally use IP processing and IP storage: the crucial difference . Security data should be dedicated, access-restricted and only retained for as long as necessary.

Reset

If the reduced configuration affects a required function, restore only the relevant setting and then recheck data flow, storage, retention and third-party connections.

Related guides

Sources and verification

This guide is based on multiple current sources. Vendor documentation is not treated as proof that every concrete installation automatically follows the same privacy characteristics.

Important: IP processing is not IP storage

An IP address has to be processed to establish and deliver a network connection. Hosting providers, firewalls or DDoS protection may also process or retain it for a limited time for security purposes. No Logging distinguishes this security layer from unnecessary persistent visitor logging by the website, application and ordinary access logs.

↑