When setting log_level: debug in an appsec-config (or directly in the acquisition), it looks like the log level is not properly set on the actual logger.
With a config like this and some additional debug in crowdsec:
source: appsec
log_level: trace
appsec_configs:
- crowdsecurity/virtual-patching
labels:
type: appsec
The log level seems to be set to panic:
INFO[2025-09-05T13:35:02+02:00] log level is panic request_uuid=ecdb0231-b68d-40cf-8ebc-f3cafca44fb4 runner_uuid=7f86723b-7a02-48bb-8f7c-3afffa6a2807 type=appsec