# /etc/crowdsec/parsers/s02-enrich/nightscout-socketio-whitelist.yaml name: nightscout/socketio-whitelist description: "Whitelist Nightscout Socket.IO connections to prevent false positives" filter: >- evt.Meta.datasource_type == 'appsec' && evt.Meta.log_type == 'appsec-info' && evt.Meta.target_host in ['redacted', 'temp-ns.vobar.eu'] whitelist: reason: "Nightscout Socket.IO traffic" expression: - "evt.Meta.target_uri startsWith '/socket.io/?EIO='"