Skip to main content

Console Health Check Issues

The CrowdSec Console monitors the health of your CrowdSec stack (Security Engines, Log Processors, remediation components and blocklist integrations) and raises alerts when issues are detected.
This page lists all possible health check issues, their trigger conditions, and links to detailed troubleshooting guides.

Understanding Issue Criticalityโ€‹

  • ๐Ÿ”ฅ Critical: Immediate attention required - core functionality is impaired
  • โš ๏ธ High: Important issue that should be addressed soon - may impact protection effectiveness
  • ๐Ÿ’ก Recommended: Additional actions that improve your security posture (coming in future Stack Health iterations)
  • ๐ŸŒŸ Bonus: Optimization advice and upper-tier recommendations with strong return on value (coming in future Stack Health iterations)

Health Check Issues Overviewโ€‹

IssueCriticalitySummaryResolution
Integration for Firewall Offline๐Ÿ”ฅ CriticalFirewall has not pulled from BLaaS endpoint for 24+ hoursTroubleshooting
Integration for Firewall Pulling Zero IPsโš ๏ธ HighFirewall BLaaS integration is content is emptyTroubleshooting
Integration for RC Offline๐Ÿ”ฅ CriticalRemediation Component has not pulled from endpoint for 24+ hoursTroubleshooting
Log Processor No Alertsโš ๏ธ HighLog Processor has not generated alerts in 48 hoursTroubleshooting
Log Processor No Logs Parsed๐Ÿ”ฅ CriticalLogs read but none parsed in the last 48 hoursTroubleshooting
Log Processor No Logs Read๐Ÿ”ฅ CriticalNo logs acquired in the last 24 hoursTroubleshooting
Log Processor Offline๐Ÿ”ฅ CriticalLog Processor has not checked in with LAPI for 24+ hoursTroubleshooting
Security Engine No Alertsโš ๏ธ HighNo alerts generated in the last 48 hoursTroubleshooting
Security Engine No RC๐Ÿ’ก Reco.Security Engine has no Remediation Component registeredTroubleshooting
Security Engine No Active RC๐Ÿ”ฅ CriticalAll registered Remediation Components have been inactive for 24+ hoursTroubleshooting
Security Engine Offline๐Ÿ”ฅ CriticalSecurity Engine has not reported to Console for 24+ hoursTroubleshooting
Security Engine Too Many Alertsโš ๏ธ HighMore than 250,000 alerts in 6 hoursTroubleshooting

Issue Dependenciesโ€‹

Some issues are related and share common root causes:

  • Engine No Alerts may be caused by:

    • LP No Logs Read
    • LP No Logs Parsed
    • Scenarios not installed or in simulation mode
  • LP No Alerts may be caused by:

    • LP No Logs Read
    • LP No Logs Parsed
    • Scenarios not matching the parsed events

Understanding these dependencies helps you troubleshoot faster by addressing root causes first.

Future Enhancementsโ€‹

For planned and experimental health checks, see Future Console Health Check Issues for features including:

  • Enhanced configuration validation
  • Blocklists optimization recommendations
  • Collection update notifications
  • False positive prevention checks
  • Premium feature recommendation based on detected benefit

Getting Helpโ€‹

If you've followed the troubleshooting guides and still need assistance:

CrowdSec Docs
We use cookies

This site uses cookies to help us improve your experience. You can accept or decline below.