Custom Decoder & Rules
What is decoder ?
2025-03-06T10:52:53.005505+05:30 workstation fail2ban.actions[17409]: NOTICE [sshd] Ban 3.3.3.117
2025-03-06T10:53:48.522507+05:30 workstation fail2ban.actions[17409]: NOTICE [sshd] Unban 3.3.3.1172025-03-06T10:50:52.298830+05:30 workstation fail2ban-server[17298]: Server ready
2025-03-06T10:51:11.811298+05:30 workstation fail2ban.server[17298]: INFO Exiting Fail2ban2025-03-06T11:04:48.072538+05:30 workstation fail2ban.observer[17990]: NOTICE [sshd] Increase Ban 3.3.3.117 (2 # 2m -> 2025-03-06 11:06:47)<decoder name="example">
<program_name>^example</program_name>
</decoder>
<decoder name="example">
<parent>example</parent>
<regex>User '(\w+)' logged from '(\d+.\d+.\d+.\d+)'</regex>
<order>user, srcip</order>
</decoder>


Last updated