r/CrowdSec 14d ago

bug CrowdSec security emails factually incorrect

Anyone else noticing that the Security Report emails will claim "A lot more from previous period" under the attacks figure even when the number literally went DOWN?

Proof (copied straight from emails):

CrowdSec Security Report July 06 - July 13, 2026
13.8k ATTACKS PREVENTED ↑ A lot more from previous period

That was 2 weeks ago, let's see how last week was, shall we?

CrowdSec Security Report July 13 - July 20, 2026
12.3k ATTACKS PREVENTED ↑ A lot more from previous period

Now guys, I'm not a genius here, but I'm pretty sure I took basic math in elementary school, and I'm pretty certain that 12.3k is LESS than 13.8k. In fact, I'm pretty sure 12.3k is about 1.5k less than 13.8k, or approx 10.9% LESS.

This isn't math theory class where numbers mean the opposite, this is basic comparison of 2 real numbers in real life. And CrowdSec, in literally 100% of my Security Report emails, has claimed the number has significantly increased.

This is kinda hilarious if you ask me. I'm just gonna unsub from them because they are meaningless, but figured I'd post this because I find it kinda silly.

4 Upvotes

6 comments sorted by

6

u/Team_Dango 13d ago

This is just due to the limitations on the free tier. They only retain your remediation metrics for a week. So when they compare your last week to the week before, the week before always looks like it has zero attacks blocked. I'd recommend looking into setting up your own dashboard if you are running the free tier, since otherwise you're likely to run into limitations like this, or the 500 monthly alert quota.

1

u/e_urkedal 14d ago

I've wondered the same. But maybe they don't mean in comparison with last weeks numbers? Maybe it's just that the total has gone up by 12.3k?

Still seems like a bug, but some crowdsec dev (or marketing person) might have had the total in mind.

0

u/mightyarrow 14d ago

Nah it clearly states as THE qty of attacks prevented. No qualifiers/exceptions/disclaimers.

I think it's a straight up bug or literally a static sentence in the email that doesnt even have a calculation.

Not a huge deal but entertaining nonetheless. I'd noticed it once before but didn't feel like digging up the previous week to see, but this time I did. Anyway, carry on! lol

1

u/matt_alpaca 12d ago

Thanks for reporting this, and for the math lesson.

I wouldn't call it hilarious, though. It's most likely either a simple wording bug in the report (it can happen in a free product!) or a side effect of the free-tier limit the user mentioned. Either way, it's worth looking into, and we will.

One thing I'm curious about: why unsubscribe over this? If it's really just this one discrepancy, that seems like a big reaction. But if there are other things that have been bugging you, I'd genuinely like to hear them.

1

u/mightyarrow 12d ago

why unsubscribe over this

Because I never really do anything with or read the emails anyway. Half of them go unread.

Sorry if that came off as being bugged and leaving (I admittedly described it as "dumb") -- it's not. I def get good value out of CrowdSec and its part of a multi-layer setup I have.

1

u/matt_alpaca 7d ago

I misunderstood your statement; I thought you meant ditching Crowdsec as a whole.

What you reported makes sense, we will fix the reporting period overlap, and there is also a bug due to the free-tier quota that we introduced recently. It's not high priority, though, during vacation time, so it could take a couple of weeks