Rev 5 | Blame | Compare with Previous | Last modification | View Log | RSS feed
# Fail2Ban configuration file## Author: Steven Hiscocks##[Definition]# Option: failregex# Notes.: regex to match the password failures messages in the logfile. The# host must be matched by a group named "host". The tag "<HOST>" can# be used for standard IP/hostname matching and is only an alias for# (?:::f{4,6}:)?(?P<host>[\w\-.^_]+)# Multiline regexs should use tag "<SKIPLINES>" to separate lines.# This allows lines between the matching lines to continue to be# searched for other failures. This tag can be used multiple times.# Values: TEXT#failregex = ^=INFO REPORT==== ===\nI\(<0\.\d+\.0>:ejabberd_c2s:\d+\) : \([^)]+\) Failed authentication for .+ from IP <HOST> \({{(?:\d+,){3}\d+},\d+}\)$^(?:\.\d+)? \[info\] <0\.\d+\.\d>@ejabberd_c2s:wait_for_feature_request:\d+ \([^\)]+\) Failed authentication for \S+ from IP <HOST>$# Option: ignoreregex# Notes.: regex to ignore. If this regex matches, the line is ignored.# Values: TEXT#ignoreregex =[Init]# "maxlines" is number of log lines to buffer for multi-line regex searchesmaxlines = 2# Option: journalmatch# Notes.: systemd journalctl style match filter for journal based backend# Values: TEXT#journalmatch =