Fail2ban Regex - not matching lines in log file

Viewed 468

I am trying to create a fail2ban regex against this string:

[2020-Nov-10 16:13:35] [freepbx_security.NOTICE]: Authentication failure for S from 109.38.128.48 [] []

What I've created so far is this regex:

\[.*\] \[freepbx_security\.NOTICE\]: Authentication failure for .* from <HOST> \[\] \[\]

I've changed the flavor to explicitly make use of Python. Regex101 shows a match, but my fail2ban-regex still fails to observe it.

I have created a test case with a logline in its most basic form and a most simple test against it, but even that fails:

fail2ban-regex 'Authentication failure for S from 109.38.128.48' 'Authentication failure for S from <HOST>'

Running tests
=============

Use   failregex line: Authentication failure for S from <HOST>
Use      single line: Authentication failure for S from 109.38.128.48


Results
=======

Failregex: 0 total

Ignoreregex: 0 total

Date template hits:

Lines: 1 lines, 0 ignored, 0 matched, 1 missed
[processed in 0.02 sec]

|- Missed line(s):
|  Authentication failure for S from 109.38.128.48

if I apply the

If I add the -D switch to fail2ban-regex I get a debuggex URL which shows a complete match. However, Fail2ban claims its still a miss: Link

No matter how much I fiddle with wildcards, fail2ban-regex doesn't match, while the regex does match if I test it on https://regex101.com/. I'm probably overlooking something small and stupid. Is there anybody who can guide me onto the path of enlightenment :)

1 Answers

Shortly, fail2ban searching for a date in log (and one of default date patterns matching that). You can try to add -l HEAVYDEBUG parameters fail2ban-regex to see what is happening there. And your date pattern is not matching defaults of fail2ban.

So just specify your own datepattern in jail (fail2ban version > 0.10 only) or in filter:

datepattern = ^\[%%Y-%%b-%%d %%H:%%M:%%S\]\s
failregex = ^\[freepbx_security.NOTICE\]: Authentication failure for \S+ from <ADDR>

If your fail2ban version is still 0.9, put datepattern in Init section of filter and replace <ADDR> with <HOST>.
Note that string matching datepattern is cut from line out before failregex is applied (so failregex must not contain that).

And here how it works in fail2ban-regex:

fail2ban-regex --datepattern '^\[%Y-%b-%d %H:%M:%S\]\s' '[2020-Nov-10 16:13:35] [freepbx_security.NOTICE]: Authentication failure for S from 109.38.128.48 [] []' '\[freepbx_security.NOTICE\]: Authentication failure for \S+ from <ADDR>'
Related