Since Jul 12 the stack ingests Synology DSM syslog (fids/fids2 -> Log Center -> 192.168.0.142:5514/udp), but only the published port was in the working tree and the actual config lived exclusively in the crowdsec-config named volume -- a volume reset would have silently dropped the Synology detection and the escalating ban policy. Moved into the repo and bind-mounted (single source of truth; the shadowed copies were removed from the volume): - crowdsec/acquis-synology.yaml -> acquis.d/synology.yaml (syslog listener) - crowdsec/parsers/famfihome-synology-connection.yaml -> s01-parse/ (local parser for DSM 7 "Connection" failed sign-ins -> synology-dsm-bf) - crowdsec/profiles.yaml (escalating ban (count+1)*12h, capped at 168h) Also commits the previously untracked 5514:514/udp port mapping. Verified after recreate: syslog listener bound on :514, lines arriving from 192.168.0.234, traefik access.log tail active, local parser loaded, cscli explain on a DSM sign-in failure still reaches crowdsecurity/synology-dsm-bf, 26 active decisions preserved, both bouncers pulling. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
14 lines
548 B
YAML
14 lines
548 B
YAML
# CrowdSec acquisition: Syslog-Listener fuer die Synology-NAS (fids/fids2)
|
|
# Gemountet nach /etc/crowdsec/acquis.d/synology.yaml (siehe docker-compose.yml)
|
|
#
|
|
# Die Synologies senden per DSM "Log Center -> Log Sending" an
|
|
# 192.168.0.142:5514/udp; Docker mappt das auf Port 514 im Container.
|
|
# Das Label "syslog" aktiviert s00-raw/crowdsecurity/syslog-logs; darauf
|
|
# setzen crowdsecurity/synology-dsm (+ der lokale Parser
|
|
# parsers/famfihome-synology-connection.yaml) auf.
|
|
source: syslog
|
|
listen_addr: 0.0.0.0
|
|
listen_port: 514
|
|
labels:
|
|
type: syslog
|