fail2ban.log and rsyslog
Using rsyslog on 5.8.6 on my Client, I can't seem to get /var/log/fail2ban.log from the client over to my rsyslogd 7.6.3 Server.
Fail2ban on the client is v0.8.6 in /etc/fail2ban/fail2ban.conf Code:
# Fail2Ban configuration file Code:
# 04/30/2014 11:44:50 AM Code:
fail2ban.filter.log I tried setting one manually using fail2ban-client using Code:
fail2ban-client set zimbra banip 46.201.148.246 Code:
WARNING 'socket' not defined in 'Definition'. Using default value I have bounced rsyslogd and fail2ban during this time and it has made little difference. So, is there something I have missed? Thanks! |
First thought is permissions.
|
Thanks.
kernel.log works file, so I compared: Code:
-rw-r----- 1 root adm 20834 Apr 30 19:48 /var/log/fail2ban.log Code:
-rw-r----- 1 syslog adm 20834 Apr 30 19:48 /var/log/fail2ban.log I did get a "new" file that I expect to be where I'd see some f2b 'actions' set, fail2ban.actions.log but it only shows: Code:
Apr 30 20:17:00 cirrhus9a fail2ban.actions: INFO Set banTime = 31556926 |
Well, its a start anyway! As you are certainly aware, it is best to start at the first step of setup, and work to the end and doublecheck everything, before filing a bug report :)
What is your rsyslog config of kernel compared to fail2ban? Do you have selinux enabled? I've had trouble with rsyslog and varnish because of selinux. |
Quote:
I set this after comparing to another f2b client I have and noticed these entries missing. Code:
socket = /var/run/fail2ban/fail2ban.sock Code:
fail2ban-client set zimbra banip 46.201.148.246 Code:
Apr 30 20:35:01 cirrhus9a fail2ban.actions: WARNING [zimbra] Ban 46.201.148.246 Thanks! |
I probably over-edit. But it seems like after I reply, i have more ideas... :/ Im slow like that.
Wonderful my friend, glad it worked out. Thanks for posting the solution! On another note, I used zimbra for a minute, but ended up using Zentyal community instead. Here is a link: http://www.zentyal.org/ Very nice SBS with good AD compatibility. |
Quote:
I have 3 brain cells left and 2 are fighting at the moment. Once the remaining one calls "timeout", then I have a chance to think and re-edit. Plus, I don't get of the terminal much, so I don't communicate with people too well. It's hard for me to communicate to others in simplistic terms what the issue is. My brain goes full throttle 24/7/365 Peace. |
All times are GMT -5. The time now is 12:16 AM. |