The 1.7.0 release of crowdsec brings some major changes to how services are auto-detected during installation, and to the metrics shared by the log processors to LAPI.
The new detection system, cscli setup, is much more flexible and powerful:
Supports Linux, BSD and Windows (at the time, auto-detection is only performed at install time for deb and RPM packages)
More services are detected out of the box
A custom detection configuration can be provided during installation to detect custom services and generate custom acquisition configs (eg, when not using default log paths)
The auto-detection can be skipped if the configuration is managed with tools like Ansible
The Log Processors now send metrics about the acquisition (number of lines read and parsed per datasource) and the parsers (number of events parsed, unparsed, or whitelisted) to LAPI.
Those metrics are shown when running cscli machines inspect XXX.
In the future, they will also be displayed in the console and used to detect potentially misconfigured or misbehaving installations.
Other notable changes include:
Support for swarm in the docker datasource
Better CRS integration in the WAF (this will continue to be improved over time)
New expr helpers to compute the average and median time between events
[!WARNING]
Starting with this release, when crowdsec is run in a docker (or podman) container, a volume must be provided /var/lib/crowdsec/data/, otherwise the container will refuse to start.
This requirement does not apply to Kubernetes.
[!NOTE]
As previously documented here, the cscli dashboard command has been removed.
If you are still using the metabase dashboard, we recommend you migrate to https://app.crowdsec.net
This PR contains the following updates:
| Package | Update | Change |
|---|---|---|
| [ghcr.io/crowdsecurity/crowdsec](https://github.com/crowdsecurity/crowdsec) | minor | `v1.6.11` -> `v1.7.0` |
---
### Release Notes
<details>
<summary>crowdsecurity/crowdsec (ghcr.io/crowdsecurity/crowdsec)</summary>
### [`v1.7.0`](https://github.com/crowdsecurity/crowdsec/releases/tag/v1.7.0)
[Compare Source](https://github.com/crowdsecurity/crowdsec/compare/v1.6.11...v1.7.0)
The 1.7.0 release of crowdsec brings some major changes to how services are auto-detected during installation, and to the metrics shared by the log processors to LAPI.
The new detection system, `cscli setup`, is much more flexible and powerful:
- Supports Linux, BSD and Windows (at the time, auto-detection is only performed at install time for deb and RPM packages)
- More services are detected out of the box
- A custom detection configuration can be provided during installation to detect custom services and generate custom acquisition configs (eg, when not using default log paths)
- The auto-detection can be skipped if the configuration is managed with tools like Ansible
Learn more about it in [our documentation](https://docs.crowdsec.net/docs/log_processor/service-discovery-setup/intro).
The Log Processors now send metrics about the acquisition (number of lines read and parsed per datasource) and the parsers (number of events parsed, unparsed, or whitelisted) to LAPI.
Those metrics are shown when running `cscli machines inspect XXX`.
In the future, they will also be displayed in the console and used to detect potentially misconfigured or misbehaving installations.
Other notable changes include:
- Support for swarm in the docker datasource
- Better CRS integration in the WAF (this will continue to be improved over time)
- New expr helpers to compute the average and median time between events
> \[!WARNING]
> Starting with this release, when crowdsec is run in a docker (or podman) container, a volume *must* be provided `/var/lib/crowdsec/data/`, otherwise the container will refuse to start.
> This requirement does not apply to Kubernetes.
> \[!NOTE]
> As previously documented [here](https://docs.crowdsec.net/blog/cscli_dashboard_deprecation/), the `cscli dashboard` command has been removed.
> If you are still using the metabase dashboard, we recommend you migrate to <https://app.crowdsec.net>
##### Changes
- use go 1.24.6 ([#​3835](https://github.com/crowdsecurity/crowdsec/issues/3835)) [@​mmetc](https://github.com/mmetc)
- CI: update actions; drop version comments ([#​3823](https://github.com/crowdsecurity/crowdsec/issues/3823)) [@​mmetc](https://github.com/mmetc)
- install scripts: echo -e -> echo (we're not requiring bash anymore) ([#​3799](https://github.com/crowdsecurity/crowdsec/issues/3799)) [@​mmetc](https://github.com/mmetc)
- move detect.yaml to /var/lib/crowdsec/data ([#​3797](https://github.com/crowdsecurity/crowdsec/issues/3797)) [@​mmetc](https://github.com/mmetc)
- restore wizard.sh --unattended ([#​3790](https://github.com/crowdsecurity/crowdsec/issues/3790)) [@​mmetc](https://github.com/mmetc)
- cleanup wizard.sh ([#​3786](https://github.com/crowdsecurity/crowdsec/issues/3786)) [@​mmetc](https://github.com/mmetc)
- remove the cscli\_setup feature flag ([#​3784](https://github.com/crowdsecurity/crowdsec/issues/3784)) [@​mmetc](https://github.com/mmetc)
- add detect.yaml in rpm files section ([#​3773](https://github.com/crowdsecurity/crowdsec/issues/3773)) [@​sabban](https://github.com/sabban)
- refact whitelist/allowlist: net.IP to net/netip ([#​3683](https://github.com/crowdsecurity/crowdsec/issues/3683)) [@​mmetc](https://github.com/mmetc)
- refact: pkg/database decisions filter, queries ([#​3635](https://github.com/crowdsecurity/crowdsec/issues/3635)) [@​mmetc](https://github.com/mmetc)
##### New Features
- cscli: remove "dashboard" command ([#​3004](https://github.com/crowdsecurity/crowdsec/issues/3004)) [@​mmetc](https://github.com/mmetc)
- clean up buckets serialization code ([#​3777](https://github.com/crowdsecurity/crowdsec/issues/3777)) [@​sabban](https://github.com/sabban)
- cscli setup: new service detection and configuration ([#​3730](https://github.com/crowdsecurity/crowdsec/issues/3730)) [@​mmetc](https://github.com/mmetc)
- feat: add swarm support to docker acquistion ([#​3744](https://github.com/crowdsecurity/crowdsec/issues/3744)) [@​LaurenceJJones](https://github.com/LaurenceJJones)
##### Improvements
- WAF: Improve user-experience with CRS and modsecurity rules ([#​3827](https://github.com/crowdsecurity/crowdsec/issues/3827)) [@​blotus](https://github.com/blotus)
- cscli setup: allow skipping service detection with $CROWDSEC\_SETUP\_UN… ([#​3822](https://github.com/crowdsecurity/crowdsec/issues/3822)) [@​mmetc](https://github.com/mmetc)
- cscli setup: improve service detection and datasource validation ([#​3812](https://github.com/crowdsecurity/crowdsec/issues/3812)) [@​mmetc](https://github.com/mmetc)
- cscli setup: skip missing items, fix collection name ([#​3794](https://github.com/crowdsecurity/crowdsec/issues/3794)) [@​mmetc](https://github.com/mmetc)
- Improve the output of appsec `cscli hubtest` ([#​3791](https://github.com/crowdsecurity/crowdsec/issues/3791)) [@​buixor](https://github.com/buixor)
- cscli setup improvements ([#​3789](https://github.com/crowdsecurity/crowdsec/issues/3789)) [@​mmetc](https://github.com/mmetc)
- cscli: print command name along with errors ([#​3768](https://github.com/crowdsecurity/crowdsec/issues/3768)) [@​mmetc](https://github.com/mmetc)
- enhance: Add 2 time helpers for average and median ([#​3748](https://github.com/crowdsecurity/crowdsec/issues/3748)) [@​LaurenceJJones](https://github.com/LaurenceJJones)
- usage metrics: report acquisition + parsers metrics to LAPI ([#​3709](https://github.com/crowdsecurity/crowdsec/issues/3709)) [@​blotus](https://github.com/blotus)
- improve datasource validation (goccy/go-yaml) ([#​3646](https://github.com/crowdsecurity/crowdsec/issues/3646)) [@​mmetc](https://github.com/mmetc)
##### Bug Fixes
- fix "cscli alerts list -s <scenario>" for alerts with no decisions ([#​3830](https://github.com/crowdsecurity/crowdsec/issues/3830)) [@​mmetc](https://github.com/mmetc)
- unify the output format of start\_at and stop\_at ([#​3819](https://github.com/crowdsecurity/crowdsec/issues/3819)) [@​buixor](https://github.com/buixor)
- pkg/cwhub: fix relative symlink resolution ([#​3824](https://github.com/crowdsecurity/crowdsec/issues/3824)) [@​mmetc](https://github.com/mmetc)
- fix: Postint check also if api.server.enable is false ([#​3802](https://github.com/crowdsecurity/crowdsec/issues/3802)) [@​LaurenceJJones](https://github.com/LaurenceJJones)
- detect.yaml: always acquire ssh logs from file if present ([#​3825](https://github.com/crowdsecurity/crowdsec/issues/3825)) [@​mmetc](https://github.com/mmetc)
- detect.yaml: avoid double acquisition on deb ([#​3821](https://github.com/crowdsecurity/crowdsec/issues/3821)) [@​mmetc](https://github.com/mmetc)
- review config/detect.yaml ([#​3820](https://github.com/crowdsecurity/crowdsec/issues/3820)) [@​mmetc](https://github.com/mmetc)
- fix rpm detect.yaml ([#​3814](https://github.com/crowdsecurity/crowdsec/issues/3814)) [@​sabban](https://github.com/sabban)
- CI: remove config/detect.yaml reference from rpm ([#​3813](https://github.com/crowdsecurity/crowdsec/issues/3813)) [@​mmetc](https://github.com/mmetc)
- fix rpm dovecot detection ([#​3796](https://github.com/crowdsecurity/crowdsec/issues/3796)) [@​sabban](https://github.com/sabban)
- Increase hub download timeout to 10 minutes ([#​3785](https://github.com/crowdsecurity/crowdsec/issues/3785)) [@​mmetc](https://github.com/mmetc)
- docker: enforce volume use for /var/lib/crowdsec/data/ ([#​3757](https://github.com/crowdsecurity/crowdsec/issues/3757)) [@​blotus](https://github.com/blotus)
- setup: add detect.yaml to windows install ([#​3775](https://github.com/crowdsecurity/crowdsec/issues/3775)) [@​blotus](https://github.com/blotus)
- fix timemachine lock ([#​3767](https://github.com/crowdsecurity/crowdsec/issues/3767)) [@​sabban](https://github.com/sabban)
- appsec: properly set URI in the original request object for use in hooks ([#​3755](https://github.com/crowdsecurity/crowdsec/issues/3755)) [@​blotus](https://github.com/blotus)
##### Chore / Deps
- build(deps): bump codecov/codecov-action from 5.4.3 to 5.5.0 ([#​3816](https://github.com/crowdsecurity/crowdsec/issues/3816)) @​[dependabot\[bot\]](https://github.com/apps/dependabot)
- build(deps): bump github/codeql-action from 3.29.7 to 3.29.11 ([#​3818](https://github.com/crowdsecurity/crowdsec/issues/3818)) @​[dependabot\[bot\]](https://github.com/apps/dependabot)
- build(deps): bump github.com/crowdsecurity/machineid from 1.0.2 to 1.0.3 ([#​3769](https://github.com/crowdsecurity/crowdsec/issues/3769)) @​[dependabot\[bot\]](https://github.com/apps/dependabot)
- build(deps): bump docker/login-action from 3.4.0 to 3.5.0 ([#​3783](https://github.com/crowdsecurity/crowdsec/issues/3783)) @​[dependabot\[bot\]](https://github.com/apps/dependabot)
- update dependencies, use go 1.24.5 ([#​3774](https://github.com/crowdsecurity/crowdsec/issues/3774)) [@​mmetc](https://github.com/mmetc)
- build(deps): bump github.com/go-sql-driver/mysql from 1.6.0 to 1.9.3 ([#​3761](https://github.com/crowdsecurity/crowdsec/issues/3761)) @​[dependabot\[bot\]](https://github.com/apps/dependabot)
- build(deps): bump github.com/go-openapi/swag from 0.23.0 to 0.23.1 ([#​3763](https://github.com/crowdsecurity/crowdsec/issues/3763)) @​[dependabot\[bot\]](https://github.com/apps/dependabot)
- build(deps): bump github.com/hashicorp/go-version from 1.2.1 to 1.7.0 ([#​3764](https://github.com/crowdsecurity/crowdsec/issues/3764)) @​[dependabot\[bot\]](https://github.com/apps/dependabot)
- build(deps): bump github/codeql-action from 3.29.4 to 3.29.5 ([#​3765](https://github.com/crowdsecurity/crowdsec/issues/3765)) @​[dependabot\[bot\]](https://github.com/apps/dependabot)
- build(deps): bump github.com/alexliesenfeld/health from 0.8.0 to 0.8.1 ([#​3760](https://github.com/crowdsecurity/crowdsec/issues/3760)) @​[dependabot\[bot\]](https://github.com/apps/dependabot)
- build(deps): bump github.com/r3labs/diff/v2 from 2.14.1 to 2.15.1 ([#​3721](https://github.com/crowdsecurity/crowdsec/issues/3721)) @​[dependabot\[bot\]](https://github.com/apps/dependabot)
- build(deps): bump google.golang.org/grpc from 1.67.1 to 1.74.2 ([#​3750](https://github.com/crowdsecurity/crowdsec/issues/3750)) @​[dependabot\[bot\]](https://github.com/apps/dependabot)
- build(deps): bump github.com/go-openapi/validate from 0.20.0 to 0.24.0 ([#​3719](https://github.com/crowdsecurity/crowdsec/issues/3719)) @​[dependabot\[bot\]](https://github.com/apps/dependabot)
- build(deps): bump github.com/sanity-io/litter from 1.5.5 to 1.5.8 ([#​3720](https://github.com/crowdsecurity/crowdsec/issues/3720)) @​[dependabot\[bot\]](https://github.com/apps/dependabot)
- build(deps): bump golang.org/x/net from 0.41.0 to 0.42.0 ([#​3749](https://github.com/crowdsecurity/crowdsec/issues/3749)) @​[dependabot\[bot\]](https://github.com/apps/dependabot)
- build(deps): bump astral-sh/setup-uv from 6.4.1 to 6.4.3 ([#​3753](https://github.com/crowdsecurity/crowdsec/issues/3753)) @​[dependabot\[bot\]](https://github.com/apps/dependabot)
- build(deps): bump github/codeql-action from 3.29.2 to 3.29.4 ([#​3751](https://github.com/crowdsecurity/crowdsec/issues/3751)) @​[dependabot\[bot\]](https://github.com/apps/dependabot)
- build(deps): bump golang.org/x/mod from 0.25.0 to 0.26.0 ([#​3746](https://github.com/crowdsecurity/crowdsec/issues/3746)) @​[dependabot\[bot\]](https://github.com/apps/dependabot)
##### Geolite2 notice
This product includes GeoLite2 data created by MaxMind, available from <a href="https://www.maxmind.com"><https://www.maxmind.com></a>.
##### Installation
Take a look at the [installation instructions](https://doc.crowdsec.net/docs/getting_started/install_crowdsec).
</details>
---
### Configuration
📅 **Schedule**: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).
🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.
♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about this update again.
---
- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box
---
This PR has been generated by [Renovate Bot](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0MS4xMjUuMyIsInVwZGF0ZWRJblZlciI6IjQxLjEyNS4zIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJyZW5vdmF0ZSJdfQ==-->
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
This PR contains the following updates:
v1.6.11->v1.7.0Release Notes
crowdsecurity/crowdsec (ghcr.io/crowdsecurity/crowdsec)
v1.7.0Compare Source
The 1.7.0 release of crowdsec brings some major changes to how services are auto-detected during installation, and to the metrics shared by the log processors to LAPI.
The new detection system,
cscli setup, is much more flexible and powerful:Learn more about it in our documentation.
The Log Processors now send metrics about the acquisition (number of lines read and parsed per datasource) and the parsers (number of events parsed, unparsed, or whitelisted) to LAPI.
Those metrics are shown when running
cscli machines inspect XXX.In the future, they will also be displayed in the console and used to detect potentially misconfigured or misbehaving installations.
Other notable changes include:
Changes
New Features
Improvements
cscli hubtest(#3791) @buixorBug Fixes
Chore / Deps
Geolite2 notice
This product includes GeoLite2 data created by MaxMind, available from https://www.maxmind.com.
Installation
Take a look at the installation instructions.
Configuration
📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR has been generated by Renovate Bot.