LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 09-01-2022, 07:20 AM   #1
HQuest
Member
 
Registered: Jan 2018
Location: 2001:470:c2d0::/56
Distribution: Anyone that I can interface with
Posts: 88

Rep: Reputation: Disabled
fail2ban: writing offenders to a file


Hi folks.

While I understand fail2ban can automatically place offenders into firewall policies, how can I make the system write IP addresses into a text file? I know there is the "fail2ban-client banned" command option that shows me a list however it sounds counter-intuitive to have to run something a second time to extract this data.

Thanks.
 
Old 09-01-2022, 08:08 AM   #2
bathory
LQ Guru
 
Registered: Jun 2004
Location: Piraeus
Distribution: Slackware
Posts: 13,163
Blog Entries: 1

Rep: Reputation: 2032Reputation: 2032Reputation: 2032Reputation: 2032Reputation: 2032Reputation: 2032Reputation: 2032Reputation: 2032Reputation: 2032Reputation: 2032Reputation: 2032
Quote:
Originally Posted by HQuest View Post
Hi folks.

While I understand fail2ban can automatically place offenders into firewall policies, how can I make the system write IP addresses into a text file? I know there is the "fail2ban-client banned" command option that shows me a list however it sounds counter-intuitive to have to run something a second time to extract this data.

Thanks.
AFAIK fail2ban uses /var/log/fail2ban.log to log its actions.
 
1 members found this post helpful.
Old 09-01-2022, 08:33 AM   #3
HQuest
Member
 
Registered: Jan 2018
Location: 2001:470:c2d0::/56
Distribution: Anyone that I can interface with
Posts: 88

Original Poster
Rep: Reputation: Disabled
Quote:
Originally Posted by bathory View Post
AFAIK fail2ban uses /var/log/fail2ban.log to log its actions.
Thanks, but then I still need to somehow parse this file for "NOTICE [jail name] Ban x.x.x.x" messages. I'm trying to avoid doing manual parsing.
 
Old 09-01-2022, 08:54 AM   #4
boughtonp
Senior Member
 
Registered: Feb 2007
Location: UK
Distribution: Debian
Posts: 3,610

Rep: Reputation: 2553Reputation: 2553Reputation: 2553Reputation: 2553Reputation: 2553Reputation: 2553Reputation: 2553Reputation: 2553Reputation: 2553Reputation: 2553Reputation: 2553

You don't want to use the built-in functionality, but you also don't want to parse the logs yourself?

Unless you're going to modify fail2ban-server to implement custom extra logging, I'm fairly sure you have to pick one of those.

What's your reason for wanting to write the IPs to a text file?

 
Old 09-01-2022, 09:19 AM   #5
HQuest
Member
 
Registered: Jan 2018
Location: 2001:470:c2d0::/56
Distribution: Anyone that I can interface with
Posts: 88

Original Poster
Rep: Reputation: Disabled
Quote:
Originally Posted by boughtonp View Post
You don't want to use the built-in functionality, but you also don't want to parse the logs yourself?

Unless you're going to modify fail2ban-server to implement custom extra logging, I'm fairly sure you have to pick one of those.

What's your reason for wanting to write the IPs to a text file?

I want to get these IPs sent to other systems and exchange this data, so I don't need to wait certain actions to happen before I take action. However, I actually found a way to do it - via action.d/ that I completely forgot. Thanks for the hints, though.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
LXer: Weekend Project: Keep Out Repeat Offenders with Fail2ban on Linux LXer Syndicated Linux News 0 07-17-2011 12:10 PM
LXer: Red Hat flags OSI offenders on partner site LXer Syndicated Linux News 0 07-25-2007 09:48 PM
Sex Offenders. Are there more of them today? randell6564 General 29 09-23-2006 08:23 AM
sex offenders in chats crAckZ General 61 03-30-2006 10:38 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 09:43 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration