GLPI配置Fail2ban正则匹配异常求助:failregex无匹配但ignoreregex生效
Hi folks,
I'm setting up Fail2ban to secure my GLPI instance against brute-force attacks, but I'm hitting a confusing regex issue. Let me break down what I've tried:
My Fail2ban Setup
Jail Configuration (
/etc/fail2ban/jail.conf):[glpi] enabled = true filter = glpi port = http, https logpath = /var/www/glpi/files/_log/event.log maxretry = 3Filter File (
/etc/fail2ban/filter.d/glpi.conf):[INCLUDES] before = common.conf [Definition] failregex = Connexion échouée de \w+ depuis l\’IP <HOST> ignoreregex = /etc/init.d/fail2ban restart
The Issue
When I test the filter with this command:
fail2ban-regex /var/www/glpi/files/_log/event.log /etc/fail2ban/filter.d/glpi.conf
The result shows 0 matches for the failregex.
But here's the strange part: if I move the regex to the ignoreregex section like so:
[INCLUDES] before = common.conf [Definition] failregex = ignoreregex = Connexion échouée de \w+ depuis l\’IP <HOST>
Running the same test command now reports 20 lines being ignored—which confirms the regex itself is correctly matching the log entries.
I know the <HOST> tag is required for Fail2ban (it maps to (?:::f{4,6}:)?(?P<host>\S+) to capture IPs for iptables blocking), so that shouldn't be the problem.
Has anyone else encountered this exact behavior? Or does anyone have tips for debugging why the regex works in ignoreregex but not failregex?
内容的提问来源于stack exchange,提问作者curumo29

