Skip to main content

Upgrade and configure Premium

This guide covers the upgrade process itself and the configuration steps that follow. Complete Plan your Premium deployment before you start here.


Before you beginโ€‹

RequirementDetail
Organization roleOrganization Admin
BillingA valid payment method on the account
ScopeThe upgrade applies to one organization; repeat for each organization you want on Premium
Recommended engine versionLatest stable release of CrowdSec Agent

Upgrade your organizationโ€‹

  1. Log in to the CrowdSec Console.
  2. Switch to the organization you want to upgrade using the organization switcher in the top-left corner.
  3. Navigate to Organization Settings โ†’ Plan.
  4. Select Upgrade to Premium and choose your plan.
  5. Enter payment details or confirm the 30-day trial.
  6. Confirm the upgrade.

Premium entitlements are active immediately after confirmation.


What changes immediatelyโ€‹

The following entitlements are unlocked automatically the moment you upgrade. No additional configuration is needed for them to take effect.

FeatureWhat changes
Community Blocklist (Premium)Your enrolled Security Engines begin receiving the top 50k IP list instead of 3k
Alert quotaRaised to 10k alerts per Security Engine per month
Alert retentionExtended to 365 days
Threat Forecast BlocklistGenerated automatically from your organization's shared signals; no action required
Console IP investigationsRaised to 100 per week
CTI API callsRaised to 1,500 per month
Organization seatsExpanded to 5 included seats
Am I Under AttackAvailable in the Console immediately

What requires configurationโ€‹

These features are available after upgrading but do not become active until you configure them.

Subscribe to Premium blocklistsโ€‹

Premium tier blocklists and unlimited subscriptions are unlocked, but you must subscribe to each list you want.

  1. Go to Blocklists in the Console.
  2. Browse the Premium-tier lists.
  3. Subscribe to the lists relevant to your infrastructure (bruteforce, botnets, TOR, scanners, proxies, and so on).

Blocklist subscriptions โ†’

Enable Remediation Syncโ€‹

Remediation Sync propagates decisions from the Console to all enrolled Security Engines and blocklist integration endpoints. It is off by default.

  1. Go to Organization Settings โ†’ Remediation Sync.
  2. Enable Remediation Sync for the organization.
  3. Verify that your Security Engines are enrolled and reachable.

Remediation Sync โ†’

Enable Background Noise filteringโ€‹

Background Noise filtering removes mass-scanner and crawler traffic from your alert view. Choose a level (Low, Medium, or High) based on how aggressively you want to suppress background activity.

  1. Go to Alerts โ†’ Background Noise.
  2. Select a filtering level.
  3. Apply.

Background Noise filtering โ†’

Invite team membersโ€‹

Premium includes 5 seats. Add team members with appropriate roles.

  1. Go to Organization Settings โ†’ Members.
  2. Invite members by email.
  3. Assign roles: Viewer, Editor, or Admin.

Organization seats and roles โ†’

Configure notificationsโ€‹

Set up push notifications so your team receives alerts when Security Engines go offline, become outdated, or when abnormal attack surges are detected.

  1. Go to Organization Settings โ†’ Notifications.
  2. Connect integrations (Slack, PagerDuty, webhooks, or others).
  3. Configure which events trigger each notification channel.

Notification integrations โ†’

Create Service API credentialsโ€‹

The Service API allows programmatic management of blocklists, decisions, and enrollments. Access requires credentials scoped to your organization.

  1. Go to Organization Settings โ†’ Service API.
  2. Create a new API key.
  3. Note the key โ€” it is shown only once.

Service API โ†’

Enable Auto Enrollโ€‹

Auto Enroll lets new Security Engines join your organization automatically when they are deployed with your enrollment key, without manual approval in the Console.

  1. Go to Organization Settings โ†’ Auto Enroll.
  2. Enable Auto Enroll.
  3. Use the organization enrollment key in your deployment configuration.

Configure centralized allowlistsโ€‹

Create organization-wide allowlists that apply to all enrolled Security Engines and integrations. These replace per-engine allowlists.

  1. Go to Allowlists in the Console.
  2. Create allowlist entries.
  3. Set expiration dates for temporary allowlisting if needed.

Centralized allowlists โ†’


Feature states at a glanceโ€‹

FeatureState after upgrading
Community Blocklist (50k)Automatic
Threat Forecast BlocklistAutomatic
Extended alert quotaAutomatic
365-day retentionAutomatic
Increased Console IP investigationsAutomatic
Increased CTI API quotaAutomatic
Am I Under AttackAutomatic โ€” check Console for alerts
Premium blocklist subscriptionsRequires subscribing to each list
Remediation SyncRequires enabling
Background Noise filteringRequires enabling and selecting a level
Additional team seatsRequires inviting members
Push notificationsRequires connecting integrations
Service APIRequires creating API credentials
Auto EnrollRequires enabling
Centralized allowlistsRequires creating entries

Verify your upgradeโ€‹

After completing configuration, confirm the following.

  • Organization plan shows Premium in Organization Settings โ†’ Plan
  • Security Engines show the Premium Community Blocklist in their active blocklists
  • Alert quota and retention settings reflect Premium limits (check Alerts โ†’ Quotas)
  • Remediation Sync is enabled and shows enrolled engines as reachable
  • At least one team member has been invited (if applicable)
  • Notifications are connected and receiving test events

Downgrading or ending a trialโ€‹

If you downgrade or let a trial expire without converting:

ItemWhat happens
Community BlocklistReverts to top 3k IPs
Alert quotaReturns to 500 per month
Alert retentionReturns to 60 days; alerts older than 60 days become inaccessible
Remediation SyncDisabled; engines stop receiving centralized decisions
Background NoiseDisabled
Am I Under AttackDisabled
Premium blocklist subscriptionsReverted to 3 maximum; excess subscriptions are deactivated
Service API credentialsDeactivated
Team seats above 1Members above the Community limit lose access
Historical alert dataData beyond the Community retention window is not deleted immediately but becomes inaccessible until you re-upgrade

Contact CrowdSec support if you have questions about data retention during a plan change.


Continue to Evaluate your Premium trial โ†’

CrowdSec Docs
We use cookies

This site uses cookies to help us improve your experience. You can accept or decline below.