You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

求适用于FlashMQ日志的fail2ban正则表达式

FlashMQ日志适配Fail2Ban的正则表达式方案

日志示例

[2025-01-13 08:26:40.077] [NOTICE] [main] Accepting connection from: address='199.45.155.91', transport='TCP/Websocket/SSL', fd=20 [2025-01-13 08:26:40.078] [ERROR] [T 0] Packet read/write error: Problem accepting SSL socket: error:0A0000C1:SSL routines::no shared cipher. Removing client [ClientID='', username='', fd=20, keepalive=10s, transport='TCP/Websocket/SSL', address='199.45.155.91', prot=none, clean=0] [2025-01-13 08:26:40.078] [NOTICE] [T 0] Removing client '[ClientID='', username='', fd=20, keepalive=10s, transport='TCP/Websocket/SSL', address='199.45.155.91', prot=none, clean=0]'. Reason(s): Problem accepting SSL socket: error:0A0000C1:SSL routines::no shared cipher

现有正则的问题

你之前编写的failregex = ^Problem accepting SSL.*<HOST>.*$无法匹配日志的原因:

  • 日志中Problem accepting SSL并非行首内容,^锚定行首会导致匹配失败
  • <HOST>的匹配位置模糊,.*可能跳过IP或者匹配到无关内容,无法精准提取客户端IP

适配的正则表达式

针对你的FlashMQ日志格式,提供两个可用的正则方案:

方案1:匹配ERROR级别的SSL错误行

这个正则精准定位到ERROR日志行,提取出现SSL cipher问题的客户端IP:

failregex = ^\[[0-9:-]+\] \[ERROR\].*Problem accepting SSL socket.*address='<HOST>'

方案2:匹配NOTICE级别的客户端移除行

如果需要匹配客户端被移除的通知行,可使用这个正则:

failregex = ^\[[0-9:-]+\] \[NOTICE\].*Reason\(s\): Problem accepting SSL socket.*address='<HOST>'

正则验证方法

使用Fail2Ban自带的工具验证正则是否能正确匹配日志:

fail2ban-regex /var/log/flashmq.log "^\[[0-9:-]+\] \[ERROR\].*Problem accepting SSL socket.*address='<HOST>'"

内容的提问来源于stack exchange,提问作者stackunderflow

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.14 23:18:22