mirror of https://github.com/fail2ban/fail2ban
commit
e4c2f303bd
|
@ -0,0 +1,9 @@
|
||||||
|
# Fail2Ban filter for Centreon Web
|
||||||
|
# Detecting unauthorized access to the Centreon Web portal
|
||||||
|
# typically logged in /var/log/centreon/login.log
|
||||||
|
|
||||||
|
[Init]
|
||||||
|
datepattern = ^%%Y-%%m-%%d %%H:%%M:%%S
|
||||||
|
|
||||||
|
[Definition]
|
||||||
|
failregex = ^(?:\|-?\d+){3}\|\[[^\]]*\] \[<HOST>\] Authentication failed for '<F-USER>[^']+</F-USER>'
|
|
@ -821,6 +821,10 @@ udpport = 1200,27000,27001,27002,27003,27004,27005,27006,27007,27008,27009,27010
|
||||||
action = %(banaction)s[name=%(__name__)s-tcp, port="%(tcpport)s", protocol="tcp", chain="%(chain)s", actname=%(banaction)s-tcp]
|
action = %(banaction)s[name=%(__name__)s-tcp, port="%(tcpport)s", protocol="tcp", chain="%(chain)s", actname=%(banaction)s-tcp]
|
||||||
%(banaction)s[name=%(__name__)s-udp, port="%(udpport)s", protocol="udp", chain="%(chain)s", actname=%(banaction)s-udp]
|
%(banaction)s[name=%(__name__)s-udp, port="%(udpport)s", protocol="udp", chain="%(chain)s", actname=%(banaction)s-udp]
|
||||||
|
|
||||||
|
[centreon]
|
||||||
|
port = http,https
|
||||||
|
logpath = /var/log/centreon/login.log
|
||||||
|
|
||||||
# consider low maxretry and a long bantime
|
# consider low maxretry and a long bantime
|
||||||
# nobody except your own Nagios server should ever probe nrpe
|
# nobody except your own Nagios server should ever probe nrpe
|
||||||
[nagios]
|
[nagios]
|
||||||
|
|
|
@ -0,0 +1,4 @@
|
||||||
|
# Access of unauthorized host in /var/log/centreon/login.log
|
||||||
|
# failJSON: { "time": "2019-10-21T18:55:15", "match": true , "host": "50.97.225.132" }
|
||||||
|
2019-10-21 18:55:15|-1|0|0|[WEB] [50.97.225.132] Authentication failed for 'admin' : password mismatch
|
||||||
|
|
Loading…
Reference in New Issue